About the company
Join a highly distributed security engineering team responsible for the authorization systems that determine what users, tokens, and automated agents can access across a large-scale software platform.
Responsibilities
- Design, implement, and operate authorization capabilities within a large Ruby on Rails application, including permission checks that may execute hundreds of times within a single request.
- Own technical workstreams end to end, from problem definition and architecture through feature-flagged deployment, dual-run verification, migration, and cleanup.
- Develop and expand fine-grained permissions for tokens and roles while maintaining a coherent and scalable permission catalog.
- Strengthen authorization enforcement across GraphQL and REST APIs and improve the security, reliability, and performance of existing authorization systems.
- Refactor established policy code so authorization definitions can be evaluated consistently by both the existing application and the next-generation policy engine without changing customer behavior.
- Contribute to the migration toward a shared authorization platform using technologies such as Rust, gRPC, relationship-based authorization, and policy languages.
- Partner with authentication, platform, AI, and modular-service teams to establish clear interface contracts and support the adoption of shared authorization capabilities.
- Identify and address technical debt within the permission model while maintaining strong backward compatibility and operational safety.
- Document architectural and technical decisions through design documents, architecture records, code reviews, and other asynchronous collaboration practices.
Requirements
- Significant professional experience building and operating production Ruby on Rails applications, with strong software engineering and coding fundamentals.
- Demonstrated experience designing or implementing authorization systems, including role-based access control, fine-grained permissions, or related identity and policy-management solutions.
- A strong security mindset, with the ability to treat authorization defects as security issues and assess potential blast radius before making architectural or implementation decisions.
- Experience working safely within large, long-lived codebases, including incremental refactoring, feature flags, migrations, and changes that must preserve existing behavior.
- Working knowledge of GraphQL and API authorization patterns, with an understanding of how authorization decisions are enforced across application interfaces.
- Strong understanding of performance considerations at scale, particularly when permission checks are executed repeatedly within high-volume requests.
- Excellent written communication skills and the ability to make technical decisions, explain tradeoffs, and collaborate effectively through documentation and code review in an asynchronous environment.
- Experience or transferable knowledge in adjacent domains such as identity management, policy engines, platform security, or access-control systems is welcome.
- Familiarity with Rust, gRPC, Protocol Buffers, Cedar or other policy languages, Zanzibar-style authorization systems, Go, or service-oriented architecture is advantageous but not required.
- Ability to learn new technologies and contribute to an evolving authorization architecture while balancing security, reliability, performance, and maintainability.
Conditions
- Fully remote work opportunity for eligible candidates based in Canada.
- Flexible Paid Time Off designed to support autonomy and sustainable work-life balance.
- Equity compensation and access to an Employee Stock Purchase Plan.
- Team Member Resource Groups that support connection, inclusion, and community.
- Growth and Development Fund to support ongoing professional learning and career development.
- Parental Leave benefits.
- Opportunity to work in a globally distributed, asynchronous environment with colleagues across multiple countries and time zones.
- The role provides meaningful ownership over foundational security infrastructure and opportunities to work with modern authorization technologies.
- Compensation is determined according to role level, experience, skills, market data, equity considerations, and geographic location. The published U.S. base salary range is US$139,200–US$235,200; Canadian compensation is localized separately.