Jobs and Careers
GI

Senior Backend Engineer, Software Supply Chain Security: Authorization

GitLab
UKRemotefull_timeVerifiedPosted 11 Feb 2025
💰 $252,000/yr($117,600/yr$252,000/yr)

About the role

GitLab is an open core software company that develops the most comprehensive AI-powered DevSecOps Platform, used by more than 100,000 organizations. Our mission is to enable everyone to contribute to and co-create the software that powers our world. When everyone can contribute, consumers become contributors, significantly accelerating the rate of human progress. This mission is integral to our culture, influencing how we hire, build products, and lead our industry. We make this possible at GitLab by running our operations on our product and staying aligned with our values. Learn more about Life at GitLab.

An overview of this role

Help us architect and evolve our RBAC (role based access control) system. Our team's primary responsibility is to build a robust, scalable authorization system that gives customers complete control over their member access. From zero to owner.

Custom roles allow an organization to create user roles with the precise privileges and permissions required for that organization's needs. It's a valuable, paid feature that our enterprise customers increasingly depend on. As a senior engineer, you'll drive technical decisions that shape the future of our authorization system.

Beyond implementing custom permissions and building features to help owners manage their teams, you'll make critical architecture decisions to ensure the scalability, security, and performance of the product. We're at the earlier stages of the feature, giving you the opportunity to significantly influence our technical direction, including establishing conventions, design patterns, and development guidelines that will shape how the feature grows.

This role offers unique opportunities to collaborate with our "sister" team Anti-abuse to work on security-focused features. Help lead the battle against crypto-mining by architecting solutions that leverage risk models, identity verification, and pipeline verification and analysis.

What You’ll Do  

  • Design and implement scalable solutions for our RBAC system, with a focus on enterprise-grade custom permissions
  • Architect features that enable efficient team management while maintaining performance at scale
  • Make and advocate for technical decisions that ensure the long-term maintainability and scalability of Custom Roles
  • Lead technical discussions and mentor team members during the refinement process
  • Collaborate with Product Management to influence milestone planning and technical direction
  • Drive improvements to system performance, security, and reliability
  • Participate in and lead incident response when required
  • Represent the team in cross-functional technical discussions

What You’ll Bring 

  • Extensive professional experience with Ruby on Rails
  • Strong understanding of authorization systems including RBAC, ABAC
  • Deep experience with relational databases and query optimization (postgres preferred)
  • Experience designing and implementing enterprise-grade authentication systems (OAuth, SAML, SCIM, LDAP)
  • Track record of leading technical initiatives and mentoring other engineers
  • Experience diagnosing and resolving performance issues at scale
  • Strong security mindset and experience with secure coding practices
  • Demonstrated ability to make sound architectural decisions and lead technical discussions

About the team

The Authorization group is responsible for ensuring that an authenticated user has access to the proper resources within the application. We are focused on making our customizable permissions offering more robust by adding additional granular permissions every milestone. As a senior engineer, you'll play a key role in shaping the technical direction of these initiatives.

You can read about the work that the team is doing here.

How GitLab will support you