Gofundme
Gofundme~4mo ago
$262,800 – $321,200/yr

Senior Staff Software Engineer (Identity & Access Management)

United StatesUnited States·San Franciscosenior
OtherDevOps & InfrastructureSoftware EngineerSoftware Engineering
4 views0 saves0 applied

Quick Summary

Overview

Want to help us help others? We’re hiring! GoFundMe is the world's most powerful community for good, dedicated to helping people help each other.

Technical Tools
awsazuregcpdatabase-designfintechoauthsaassystem-design

GoFundMe is the world's most powerful community for good. Our community has raised more than $40 billion since 2010, connecting millions of donors, beneficiaries, and nonprofit partners on a single platform built for trust.

GoFundMe is hiring a Senior Staff Software Engineer, Identity & Access Management to lead the architecture, evolution, and reliability of our IAM platform: the foundational layer that every product team, enterprise partner, and internal service builds on. You will set the technical direction for how millions of people authenticate, how nonprofit partners federate into GoFundMe, and how engineering teams consume identity with confidence.

GoFundMe has more than one front door. Donors, organizers, and beneficiaries arrive through our consumer platform; nonprofits and their supporters, from grassroots organizations to some of the largest charitable institutions in the world, arrive through Pro. Keeping every front door open to the right people is an access problem, and this role owns the platform behind all of them, spanning consumer IAM and enterprise IAM: federation and provisioning, MFA orchestration and step-up, session and token lifecycle, and policy enforcement as a platform.

You will be one of three horizontal Identity Platform Engineers reporting to the Sr. Manager of Identity and Integrity Engineering, alongside an Identity & Risk Intelligence engineer and a Policy and Data engineer, partnering with stakeholders across the company to identify needs and build the access platform every surface consumes. The Identity & Risk Intelligence role owns knowing who someone is and how much to trust them; you own access: federation, provisioning, and policy enforcement. If you think in trust boundaries, federation patterns, and policy enforcement more than signals and scoring, this is your seat.

Candidates considered for this role will be located in the San Francisco Bay Area. There will be an in-office expectation of 3x a week.

  • Define and evolve the end-to-end IAM architecture spanning authentication, authorization, session management, and token lifecycle across consumer and enterprise contexts. Establish the trust boundaries, integration contracts, and platform primitives that make the secure path the default for every team consuming identity services.
  • Own the enterprise identity onboarding experience for our nonprofit customers: repeatable, self-service SSO, SCIM provisioning, and multi-tenant trust patterns that scale without bespoke integration per partner.
  • Architect federation and provisioning patterns (OIDC, SAML 2.0, SCIM) that hold up across a wide range of enterprise IdP configurations, from large institutions to small grassroots organizations.
  • Make principled build vs. integrate decisions across vendor platforms (Descope, Auth0, Okta) and in-house systems, owning the tradeoffs, migration paths, and long-term cost of change.
  • Design and operate MFA orchestration and step-up authentication flows, integrating risk signals from the Identity & Risk Intelligence engineer to make adaptive, confident auth decisions without adding unnecessary friction for the legitimate majority.
  • Own the consumer identity platform, including Descope CIAM, session management, passwordless authentication, and social login, balancing security against funnel conversion with a lean toward the enterprise and Pro surfaces where IAM complexity is highest.
  • Establish policy enforcement architecture (PEP and PAP) and the contracts by which authorization decisions are reliably enforced at runtime across consumer and enterprise surfaces.
  • Own the IAM technical roadmap, prioritizing initiatives based on user impact, enterprise requirements, compliance obligations, and technical feasibility.
  • Partner with Identity & Risk Intelligence, Payments, Security, and Integrity as the IAM platform interface for the systems that depend on it.
  • Mentor engineers across the Identity team and the broader Platform Tribe, raising the bar on system design, security thinking, and operational rigor.
  • 8+ years of software engineering experience, with significant time at senior, staff, or principal levels working on platform or infrastructure systems.
  • Deep, hands-on expertise with identity protocols and standards: OAuth 2.x, OpenID Connect, SAML 2.0, and SCIM. You can architect against these, not just integrate.
  • Track record of designing and shipping IAM or auth platforms that other engineering teams depend on in production at meaningful scale.
  • Demonstrated experience with enterprise identity at scale: SSO, SCIM provisioning, multi-tenant trust, IdP heterogeneity, and B2B platforms with a long tail of customer IdP configurations.
  • Experience architecting systems using federation standards, session and token management patterns, and well-defined trust boundaries, with an eye toward minimizing the cost of future change.
  • Strong security instincts: you threat-model as you design, understand credential risk and account takeover patterns, and build systems where the secure path is the easy path.
  • Strong observability and reliability skills: experience with monitoring, alerting, and incident response for mission-critical identity infrastructure.

Nice to Have

~1 min read
  • Hands-on experience with commercial identity platforms (Descope, Auth0, Okta, Ping, or comparable) in production, including migration between providers.
  • Experience spanning both enterprise and consumer identity contexts, such as at fintech, SaaS, payments, or identity-forward companies.
  • Familiarity with advanced authorization models (RBAC, ABAC, ReBAC) and policy engines (OPA, Cedar), particularly the enforcement side.
  • Experience with compliance and audit requirements relevant to identity systems (SOC 2, PCI DSS, GDPR, CCPA) and data residency considerations.
  • Practical experience deploying and operating identity services on cloud infrastructure (AWS, GCP, or Azure) at scale.
  • Contributions to identity standards bodies, open-source identity projects, or published thought leadership in the IAM space.
  • Make an Impact: Be part of a mission-driven organization making a positive difference in millions of lives every year.
  • Innovative Environment: Work with a diverse, passionate, and talented team in a fast-paced, forward-thinking atmosphere.
  • Collaborative Team: Join a fun and collaborative team that works hard and celebrates success together.
  • Competitive Benefits: Enjoy competitive pay and comprehensive healthcare benefits.
  • Holistic Support: Enjoy financial assistance for things like hybrid work, family planning, along with generous parental leave, flexible time-off policies, and mental health and wellness resources to support your overall well-being.
  • Growth Opportunities: Participate in learning, development, and recognition programs to help you thrive and grow.
  • Commitment to DEI: Contribute to diversity, equity, and inclusion through ongoing initiatives and employee resource groups.
  • Community Engagement: Make a difference through our volunteering program.

What We Offer

~1 min read

Depending on your location, the General Data Protection Regulation (GDPR) or certain US privacy laws may regulate the way we manage the data of job applicants. Our full notice outlining how data will be processed as part of the application procedure for applicable locations is available here. By submitting your application, you are agreeing to our use and processing of your data as required. 

We’re proud to partner with GoFundMe.org, an independent public charity, to extend the reach and impact of our generous community, while helping drive critical social change. You can learn more about GoFundMe.org’s activities and impact in their FY ‘25 annual report.

Our annual “Year in Help” report reflects our community’s impact in advancing our mission of helping people help each other.

For recent company news and announcements, visit our Newsroom.

We use Metaview as part of our hiring process for jobs in NYC and certain features may qualify it as an automated employment decision tool (AEDT), as defined by New York City Local Law 144. As part of the hiring process, we provide Metaview with job requirements and candidate submitted resumes and application materials to assist in evaluating job-related qualifications. While this tool is used to improve efficiency and support our recruiting personnel, all final hiring decisions are made by GoFundMe employees.

We began using Metaview on March 10, 2026. The Metaview tool has been reviewed by an independent auditor. Results of the audit may be viewed here. The tool evaluates your professional experience, technical skills, education, and other qualifications using information collected directly from your submitted resume and application materials; all such data is retained in accordance with GoFundMe’s Personnel Privacy Notice and applicable legal requirements. If you would like to request an alternative selection process or a reasonable accommodation, please contact accommodationrequests@gofundme.com.

Location & Eligibility

Where is the job
San Francisco, United States
On-site at the office
Who can apply
US
Listed under
United States

Listing Details

First seen
April 1, 2026
Last seen
August 14, 2026

Posting Health

Days active
135
Repost count
0
Trust Level
41%
Scored at
August 14, 2026

Signal breakdown

freshnesssource trustcontent trustemployer trust
Gofundme
Gofundme
greenhouse

GoFundMe is a global community of over 100 million people with the common purpose of helping one another.

Employees
350
Founded
2010
View company profile
Newsletter

Stay ahead of the market

Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

A
B
C
D
Join 12,000+ marketers

No spam. Unsubscribe at any time.

GofundmeSenior Staff Software Engineer (Identity & Access Management)$263k–$321k