Senior Software Engineer (Ruby), Security Platform: Authorization

JobCubby

Canada

Hybrid

CAD 120,000 - 180,000

Full time

44 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Fully remote work in Canada
Flexible Paid Time Off
Equity compensation
Employee Stock Purchase Plan
Team Member Resource Groups
Growth and Development Fund
Parental Leave

Job summary

JobCubby in Canada is seeking a Senior Software Engineer (Ruby) for a security platform focusing on authorization across a large-scale system. You will design and implement authorization checks, work with Ruby on Rails, and contribute toward a Rust-based policy engine, with emphasis on security, performance, and reliability.

You will own end-to-end workstreams from design to rollout, collaborate asynchronously with global teams, and help mature the authorization architecture while maintaining

Qualifications

  • Significant professional experience building and operating production Ruby on Rails applications.
  • Experience designing or implementing authorization systems with RBAC or fine-grained permissions.
  • Strong security mindset and ability to assess blast radius before decisions.
  • Experience working with large, long-lived codebases with feature flags and migrations.
  • Knowledge of GraphQL and API authorization patterns.
  • Understanding performance considerations for permission checks at scale.
  • Ability to learn new technologies and collaborate asynchronously in a global environment.

Responsibilities

  • Design, implement, and operate authorization capabilities within a large Ruby on Rails application.
  • Own end-to-end technical workstreams from problem definition through deployment and cleanup.
  • Develop and expand fine-grained permissions for tokens and roles.
  • Strengthen authorization enforcement across GraphQL and REST APIs.
  • Refactor policy code to be compatible with a next‑gen policy engine without changing customer behavior.
  • Contribute to migrating toward a shared authorization platform using Rust, gRPC, policy languages.
  • Partner with authentication, platform, AI, and modular‑service teams to establish clear interfaces.
  • Identify and address technical debt in the permission model while preserving backward compatibility.
  • Document architectural decisions through design documents and code reviews.

Skills

Ruby on Rails
Authorization systems
API design
GraphQL

Tools

GraphQL
REST APIs
gRPC
Protocol Buffers
Rust

Job description

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Software Engineer (Ruby), Security Platform: Authorization based in Canada.

Join a highly distributed security engineering team responsible for the authorization systems that determine what users, tokens, and automated agents can access across a large-scale software platform. You’ll work primarily in Ruby on Rails while contributing to the evolution toward a modern authorization architecture built around a Rust policy engine, relationship-based authorization, and policy languages. This role combines hands‑on software engineering with security‑focused system design and long‑term platform modernization. You’ll own significant technical workstreams from design through rollout, verification, and cleanup. Your work will directly strengthen the security, reliability, and performance of authorization at scale. You’ll collaborate asynchronously with authentication, AI, platform, and modular‑service teams across a global organization. It’s an opportunity to shape foundational security infrastructure while solving complex problems in a mature, evolving codebase.

Accountabilities
  • Design, implement, and operate authorization capabilities within a large Ruby on Rails application, including permission checks that may execute hundreds of times within a single request.
  • Own technical workstreams end to end, from problem definition and architecture through feature‑flagged deployment, dual‑run verification, migration, and cleanup.
  • Develop and expand fine‑grained permissions for tokens and roles while maintaining a coherent and scalable permission catalog.
  • Strengthen authorization enforcement across GraphQL and REST APIs and improve the security, reliability, and performance of existing authorization systems.
  • Refactor established policy code so authorization definitions can be evaluated consistently by both the existing application and the next‑generation policy engine without changing customer behavior.
  • Contribute to the migration toward a shared authorization platform using technologies such as Rust, gRPC, relationship‑based authorization, and policy languages.
  • Partner with authentication, platform, AI, and modular‑service teams to establish clear interface contracts and support the adoption of shared authorization capabilities.
  • Identify and address technical debt within the permission model while maintaining strong backward compatibility and operational safety.
  • Document architectural and technical decisions through design documents, architecture records, code reviews, and other asynchronous collaboration practices.
Requirements
  • Significant professional experience building and operating production Ruby on Rails applications, with strong software engineering and coding fundamentals.
  • Demonstrated experience designing or implementing authorization systems, including role‑based access control, fine‑grained permissions, or related identity and policy‑management solutions.
  • A strong security mindset, with the ability to treat authorization defects as security issues and assess potential blast radius before making architectural or implementation decisions.
  • Experience working safely within large, long‑lived codebases, including incremental refactoring, feature flags, migrations, and changes that must preserve existing behavior.
  • Working knowledge of GraphQL and API authorization patterns, with an understanding of how authorization decisions are enforced across application interfaces.
  • Strong understanding of performance considerations at scale, particularly when permission checks are executed repeatedly within high‑volume requests.
  • Excellent written communication skills and the ability to make technical decisions, explain tradeoffs, and collaborate effectively through documentation and code review in an asynchronous environment.
  • Experience or transferable knowledge in adjacent domains such as identity management, policy engines, platform security, or access‑control systems is welcome.
  • Familiarity with Rust, gRPC, Protocol Buffers, Cedar or other policy languages, Zanzibar‑style authorization systems, Go, or service‑oriented architecture is advantageous but not required.
  • Ability to learn new technologies and contribute to an evolving authorization architecture while balancing security, reliability, performance, and maintainability.
Benefits
  • Fully remote work opportunity for eligible candidates based in Canada.
  • Flexible Paid Time Off designed to support autonomy and sustainable work-life balance.
  • Equity compensation and access to an Employee Stock Purchase Plan.
  • Team Member Resource Groups that support connection, inclusion, and community.
  • Growth and Development Fund to support ongoing professional learning and career development.
  • Parental Leave benefits.
  • Opportunity to work in a globally distributed, asynchronous environment with colleagues across multiple countries and time zones.
  • The role provides meaningful ownership over foundational security infrastructure and opportunities to work with modern authorization technologies.
  • Compensation is determined according to role level, experience, skills, market data, equity considerations, and geographic location. The published U.S. base salary range is US$139,200–US$235,200; Canadian compensation is localized separately.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Software Engineer (Ruby), Security Platform: Authorization
Senior Software Engineer (Ruby), Security Platform: Authorization

Triwill Group • Canada

Hybrid
CAD 110,000 - 150,000
Member of Technical Staff
Member of Technical Staff

Jobgether • Canada

On-site
CAD 110,000 - 170,000
Market‑competitive salary bands
Meaningful equity program
Comprehensive health benefits
+5
Staff Software Engineer
Staff Software Engineer

Sage Recruiting Inc. • Toronto

Hybrid
CAD 170,000 - 190,000
Extended health & dental
RRSP matching
Flexible PTO
Senior Security Engineer
Senior Security Engineer

fispan • Vancouver

On-site
CAD 130,000 - 160,000
Extended health and dental benefits
Paid time off
Savings and retirement plan matching
+5
Senior Security Engineer, Application Security
Senior Security Engineer, Application Security

faire • Kitchener

Hybrid
CAD 160,000 - 220,000
Equity
Benefits
Senior Software Developer - Security - Elasticsearch
Senior Software Developer - Security - Elasticsearch

Elasticsearch B.V. • Canada

On-site
CAD 128,000 - 203,000
Health coverage for you and youramily
Flexible locations and schedules
Vacation days
+4
Senior Software Engineer — Systems
Senior Software Engineer — Systems

UrbanLogiq • Vancouver

On-site
CAD 130,000 - 160,000
Hybrid work arrangement (Vancouver, BC
Stock options
Extended health and dental benefits
+1
Director of Product Security
Director of Product Security

Motion Recruitment • Toronto

On-site
CAD 180,000 - 220,000
Medical, Dental, and Vision Insurance
Vacation Time
Stock Options
+2
Senior Cloud Security Engineer, Information Security
Senior Cloud Security Engineer, Information Security

Peoples Group • Vancouver

Hybrid
CAD 150,000 - 190,000
Hybrid work environment
Competitive salary
Profit sharing
Senior Cloud Security Engineer, Information Security
Senior Cloud Security Engineer, Information Security

Peoples Group • Toronto

Hybrid
CAD 140,000 - 180,000