Назад
Company hidden
3 дня назад

Senior Software Engineer (Ruby) (Security Platform: Authorization)

139 200 - 235 200$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
UK/US/Israel +1 еще
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Software Engineer (Ruby) (Security Platform: Authorization) (Ruby on Rails, Rust, Cedar): Building and evolving authorization systems that control access for users, tokens, and automated agents across GitLab with an accent on fine-grained permissions, policy evaluation, and API enforcement. Focus on refactoring a large authorization model, migrating it to a Rust policy engine, and maintaining performance, reliability, and security across high-volume permission checks.

Location: Remote in Canada, Israel, the United Kingdom, or the United States

Salary: $139,200–$235,200 USD per year for residents of the United States

Company

hirify.global provides an intelligent orchestration platform for DevSecOps, helping organizations improve developer productivity, operational efficiency, security, compliance, and software delivery.

What you will do

  • Design and ship authorization changes in the Ruby on Rails monolith, including systems handling hundreds of permission checks per request.
  • Own authorization workstreams from problem definition through feature-flagged rollout, dual-run verification, and cleanup.
  • Build and extend fine-grained permissions for tokens and roles while maintaining a coherent permission catalog.
  • Strengthen authorization enforcement across GraphQL and REST APIs and improve system reliability, performance, and security.
  • Refactor policy code so the Rails monolith and the Rust authorization engine can evaluate shared permission definitions without changing existing behavior.
  • Collaborate with authentication, platform, AI, and modular-service teams while documenting technical decisions in a fully asynchronous organization.

Requirements

  • Significant experience building and operating production Ruby on Rails applications.
  • Experience designing or implementing authorization systems, including role-based access control and fine-grained permissions.
  • Security mindset with the ability to assess permission bugs and their potential blast radius.
  • Experience making incremental changes to large, long-lived codebases, including feature-flagged rollouts and safe migrations.
  • Working knowledge of GraphQL, API authorization patterns, and performance considerations at scale.
  • Strong written communication for asynchronous collaboration through design documents, architecture decision records, and code reviews.

Nice to have

  • Rust, gRPC, Protocol Buffers, Cedar, Zanzibar-style authorization systems, Go, or service-oriented architecture experience.
  • Transferable experience in identity, policy engines, or platform security.

Culture & Benefits

  • Fully remote work with a distributed team working across time zones.
  • Fully asynchronous collaboration with decisions made in writing.
  • Health, financial, and well-being benefits for full-time employees.
  • Flexible paid time off, parental leave, and equity compensation.
  • Growth and development funding, an employee stock purchase plan, and team member resource groups.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →