GitLab is an open core software company that develops the most comprehensive AI-powered DevSecOps Platform, used by more than 100,000 organizations. Our mission is to enable everyone to contribute to and co-create the software that powers our world. When everyone can contribute, consumers become contributors, significantly accelerating the rate of human progress. This mission is integral to our culture, influencing how we hire, build products, and lead our industry. We make this possible at GitLab by running our operations on our product and staying aligned with our values. Learn more about Life at GitLab.
An Overview Of This Role
Help us architect and evolve our RBAC (role based access control) system. Our team's primary responsibility is to build a robust, scalable authorization system that gives customers complete control over their member access. From zero to owner.
Custom roles allow an organization to create user roles with the precise privileges and permissions required for that organization's needs. It's a valuable, paid feature that our enterprise customers increasingly depend on. As an intermediate engineer, you'll develop and implement solutions that shape the future of our authorization system.
Beyond implementing custom permissions and building features to help owners manage their teams, you'll influence critical architecture decisions to ensure the scalability, security, and performance of the product. We're at the earlier stages of the feature, giving you the opportunity to significantly influence our technical direction, including establishing conventions, design patterns, and development guidelines that will shape how the feature grows.
This role offers unique opportunities to collaborate with our "sister" team Anti-abuse to work on security-focused features. Help lead the battle against crypto-mining by architecting solutions that leverage risk models, identity verification, and pipeline verification and analysis.
What You’ll Do
What You’ll Bring
About The Team
The Authorization group is responsible for ensuring that an authenticated user has access to the proper resources within the application. We are focused on making our customizable permissions offering more robust by adding additional granular permissions every milestone.