Senior Software Engineer (Ruby), Security Platform: Authorization

JobCubby

Northern (KY)

Hybrid

USD 139,000 - 235,000

Full time

48 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Fully remote work in US
Equity compensation
Employee Stock Purchase Plan
PTO and parental leave
Growth and Development Fund
Diversity and inclusion groups
Asynchronous global team

Job summary

JobCubby in the United States seeks a Senior Software Engineer (Ruby) to lead authorization efforts within a large Rails application. You will design, implement, and operate fine-grained permissions and robust authorization checks across REST and GraphQL services as part of a modern security platform.

You will contribute to a migration toward a shared authorization platform using Rust, gRPC, and policy languages, collaborating with authentication, platform, and AI teams across a global

Qualifications

  • Significant professional experience building and operating production Ruby on Rails applications.
  • Demonstrated experience designing or implementing authorization systems, including role-based access control and fine-grained permissions.
  • Strong security mindset with attention to blast radius when making decisions.
  • Experience working safely within large, long-lived codebases with migrations and feature flags.
  • Knowledge of GraphQL and API authorization patterns.

Responsibilities

  • Design, implement, and operate authorization capabilities within a large Ruby on Rails application, including permission checks that may execute hundreds of times within a single request.
  • Own technical workstreams end to end from problem definition through deployment and cleanup.
  • Develop and expand fine-grained permissions for tokens and roles.
  • Strengthen authorization enforcement across GraphQL and REST APIs and improve security, reliability, and performance.
  • Refactor policy code to support new policy engine without changing customer behavior.
  • Contribute to migration toward a shared authorization platform using Rust, gRPC, and policy languages.
  • Partner with authentication, platform, AI, and modular-service teams to define interfaces and adoption plans.
  • Address technical debt while preserving backward compatibility and safety.
  • Document architectural decisions and design tradeoffs.

Skills

Ruby on Rails
Security engineering
API design
Performance at scale

Tools

Ruby on Rails
GraphQL
Go
gRPC
Protocol Buffers
Rust
Cedar

Job description

Senior Software Engineer (Ruby), Security Platform: Authorization based in United States

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Software Engineer (Ruby), Security Platform: Authorization based in United States.

Join a highly distributed security engineering team responsible for the authorization systems that determine what users, tokens, and automated agents can access across a large-scale software platform. You’ll work primarily in Ruby on Rails while contributing to the evolution toward a modern authorization architecture built around a Rust policy engine, relationship-based authorization, and policy languages. This role combines hands-on software engineering with security-focused system design and long-term platform modernization. You’ll own significant technical workstreams from design through rollout, verification, and cleanup. Your work will directly strengthen the security, reliability, and performance of authorization at scale. You’ll collaborate asynchronously with authentication, AI, platform, and modular-service teams across a global organization. It’s an opportunity to shape foundational security infrastructure while solving complex problems in a mature, evolving codebase.

Accountabilities
  • Design, implement, and operate authorization capabilities within a large Ruby on Rails application, including permission checks that may execute hundreds of times within a single request.
  • Own technical workstreams end to end, from problem definition and architecture through feature-flagged deployment, dual-run verification, migration, and cleanup.
  • Develop and expand fine-grained permissions for tokens and roles while maintaining a coherent and scalable permission catalog.
  • Strengthen authorization enforcement across GraphQL and REST APIs and improve the security, reliability, and performance of existing authorization systems.
  • Refactor established policy code so authorization definitions can be evaluated consistently by both the existing application and the next-generation policy engine without changing customer behavior.
  • Contribute to the migration toward a shared authorization platform using technologies such as Rust, gRPC, relationship-based authorization, and policy languages.
  • Partner with authentication, platform, AI, and modular-service teams to establish clear interface contracts and support the adoption of shared authorization capabilities.
  • Identify and address technical debt within the permission model while maintaining strong backward compatibility and operational safety.
  • Document architectural and technical decisions through design documents, architecture records, code reviews, and other asynchronous collaboration practices.
Requirements
  • Significant professional experience building and operating production Ruby on Rails applications, with strong software engineering and coding fundamentals.
  • Demonstrated experience designing or implementing authorization systems, including role-based access control, fine-grained permissions, or related identity and policy-management solutions.
  • A strong security mindset, with the ability to treat authorization defects as security issues and assess potential blast radius before making architectural or implementation decisions.
  • Experience working safely within large, long-lived codebases, including incremental refactoring, feature flags, migrations, and changes that must preserve existing behavior.
  • Working knowledge of GraphQL and API authorization patterns, with an understanding of how authorization decisions are enforced across application interfaces.
  • Strong understanding of performance considerations at scale, particularly when permission checks are executed repeatedly within high-volume requests.
  • Excellent written communication skills and the ability to make technical decisions, explain tradeoffs, and collaborate effectively through documentation and code review in an asynchronous environment.
  • Experience or transferable knowledge in adjacent domains such as identity management, policy engines, platform security, or access-control systems is welcome.
  • Familiarity with Rust, gRPC, Protocol Buffers, Cedar or other policy languages, Zanzibar-style authorization systems, Go, or service-oriented architecture is advantageous but not required.
  • Ability to learn new technologies and contribute to an evolving authorization architecture while balancing security, reliability, performance, and maintainability.
Benefits
  • Fully remote work opportunity for eligible candidates based in US.
  • Flexible Paid Time Off designed to support autonomy and sustainable work-life balance.
  • Equity compensation and access to an Employee Stock Purchase Plan.
  • Team Member Resource Groups that support connection, inclusion, and community.
  • Growth and Development Fund to support ongoing professional learning and career development.
  • Parental Leave benefits.
  • Opportunity to work in a globally distributed, asynchronous environment with colleagues across multiple countries and time zones.
  • The role provides meaningful ownership over foundational security infrastructure and opportunities to work with modern authorization technologies.
  • Compensation is determined according to role level, experience, skills, market data, equity considerations, and geographic location. The published U.S. base salary range is US$139,200-US$235,200; Canadian compensation is localized separately.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Software Engineer (Ruby), Security Platform: Authorization
Senior Software Engineer (Ruby), Security Platform: Authorization

Triwill Group • Northern (KY)

Hybrid
USD 120,000 - 180,000
Remote Senior Ruby Engineer - Authorization Platform
Remote Senior Ruby Engineer - Authorization Platform

JobCubby • Northern (KY)

Hybrid
USD 139,000 - 235,000
Fully remote work in US
Equity compensation
Employee Stock Purchase Plan
+4
Senior Ruby Engineer — Security Platform & Authorization
Senior Ruby Engineer — Security Platform & Authorization

Triwill Group • Northern (KY)

Hybrid
USD 120,000 - 180,000
Software Engineer, Authorization Infrastructure
Software Engineer, Authorization Infrastructure

Stripe • San Francisco (CA)

On-site
USD 150,000 - 210,000
Equity
Company bonus
Sales commissions/bonuses
+5
Senior Security Engineer, Platforms & AI
Senior Security Engineer, Platforms & AI

Spinwheel Solutions Inc. • Oakland (CA)

On-site
USD 140,000 - 190,000
Remote-First
Salary & Equity
Unlimited PTO
+2
Senior Software Engineer (Platform - Access & Authorization)
Senior Software Engineer (Platform - Access & Authorization)

Talanto • Northern (KY)

Hybrid
USD 186,000 - 219,000
Quarterly in-person surges
Remote-first company
Senior Staff Software Engineer
Senior Staff Software Engineer

Recruiting from Scratch • United States

Hybrid
USD 140,000 - 250,000
Software Engineer, Authorization Infrastructure
Software Engineer, Authorization Infrastructure

Monograph • Seattle (WA)

On-site
USD 157,000 - 235,000
Equity
401(k) plan
Medical, dental, and vision benefits
+1
Sr. Software Engineer
Sr. Software Engineer

Renew Financial Group • Northern (KY)

Hybrid
USD 170,000 - 200,000
PTO & holidays
Health insurance (100% company-paid)
401K with match
+5
Full Stack Software Developer (Ruby on Rails, React, Python)
Full Stack Software Developer (Ruby on Rails, React, Python)

Secure Engage • Oregon (WI)

Hybrid
USD 90,000 - 130,000
Remote-first flexibility
Equity options
Mission-driven AI product