Senior Software Engineer (Ruby), Security Platform: Authorization
The posting does not state a salary. This range is our estimate from the role, the location and the stack — treat it as a guide, not an offer.
- Level
- Senior
- Apply from
- Apply from anywhere
About the role
- Develop and maintain authorization systems in Ruby on Rails.
- Focus on fine-grained permission models and security.
- Collaborate with teams on authorization interfaces.
- Enhance reliability and performance of existing systems.
- Document technical decisions through design documents.
Skills the posting asks for
- Ruby on Rails
- GraphQL
- API
- Security
Summarised from the employer’s posting, which is reproduced in full below.
The employer’s full posting
This is a Fully Remote Job
1. About Our Client:
The organization operates in the software development and DevSecOps space, offering an intelligent orchestration platform designed to enhance developer productivity, operational efficiency, and security compliance. It supports over 50 million registered users and serves more than half of the Fortune 100 companies. The organization integrates AI into its workflows to drive innovation and impact and emphasizes a high-performance culture focused on continuous knowledge exchange and collaboration to address complex software development challenges.
2. About the Opportunity:
The Senior Software Engineer (Ruby), Security Platform: Authorization is responsible for developing and maintaining critical authorization systems that control access for users, tokens, and automated agents across the platform. This role focuses on designing and implementing fine-grained permission models and transitioning authorization logic to a next-generation stack. The position directly impacts the security and scalability of access control, ensuring robust and efficient permission enforcement.
3. Responsibilities:
- Design and implement authorization changes within a Ruby on Rails monolith handling complex permission checks.
- Own workstreams from problem definition through feature rollout and verification.
- Develop and maintain fine-grained permission catalogs and token roles.
- Extend authorization enforcement across GraphQL and REST API endpoints.
- Refactor policy code to support evaluation by both the monolith and a new authorization engine without altering current behavior.
- Enhance reliability, performance, and security of existing authorization systems.
- Collaborate with authentication, platform, AI, and modular-service teams on authorization interfaces.
- Document and communicate technical decisions through written design documents and code reviews.
4. Requirements:
- Extensive experience with production Ruby on Rails applications.
- Knowledge of authorization systems, including role-based access control and fine-grained permissions.
- Strong security mindset with attention to permission-related risks.
- Experience working with large, long-standing codebases and performing incremental, behavior-preserving changes.
- Familiarity with GraphQL and API authorization patterns.
- Awareness of performance considerations at scale.
- Strong written communication skills for asynchronous decision-making.
- Beneficial but not required: experience with Rust, gRPC, Protocol Buffers, policy languages like Cedar, Zanzibar-style authorization systems, Go, or service-oriented architectures.
5. Pay Range and Compensation Package:
- The pay range and compensation package for this role will be determined based on the candidate’s experience, skills, and other relevant factors.
Equal Opportunity Statement:
Equal Opportunity Statement: Our client is an equal opportunity employer. They celebrate diversity and are committed to creating an inclusive environment for all employees. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, or national origin.
Note:
TalentHop is a recruitment partner of this role. Please note that all employment decisions, including candidate assessment, interviews, hiring, compensation, and employment terms, are made exclusively by the hiring employer.