Job Opportunities API

The Public Ledger of Openings

← Back to the ledger

Senior Staff Software Engineer (Identity & Access Management)

GoFundMe
CompanyGoFundMe
CategoryEngineering
LocationSan Francisco
RemoteOn-site (inferred)
EmploymentNot stated
LevelSenior
SalaryNot stated by the employer
Posted1 Apr 2026
Last verified7 Aug 2026
SourceEmployer ATS (greenhouse)
Applications are handled by the employer, not by us.Apply on the employer's site →
Description
Want to help us help others? We’re hiring!  GoFundMe is the world's most powerful community for good. Our community has raised more than $40 billion since 2010, connecting millions of donors, beneficiaries, and nonprofit partners on a single platform built for trust. GoFundMe is hiring a Senior Staff Software Engineer, Identity & Access Management to lead the architecture, evolution, and reliability of our IAM platform: the foundational layer that every product team, enterprise partner, and internal service builds on. You will set the technical direction for how millions of people authenticate, how nonprofit partners federate into GoFundMe, and how engineering teams consume identity with confidence. GoFundMe has more than one front door. Donors, organizers, and beneficiaries arrive through our consumer platform; nonprofits and their supporters, from grassroots organizations to some of the largest charitable institutions in the world, arrive through Pro. Keeping every front door open to the right people is an access problem, and this role owns the platform behind all of them, spanning consumer IAM and enterprise IAM: federation and provisioning, MFA orchestration and step-up, session and token lifecycle, and policy enforcement as a platform. You will be one of three horizontal Identity Platform Engineers reporting to the Sr. Manager of Identity and Integrity Engineering, alongside an Identity & Risk Intelligence engineer and a Policy and Data engineer, partnering with stakeholders across the company to identify needs and build the access platform every surface consumes. The Identity & Risk Intelligence role owns knowing who someone is and how much to trust them; you own access: federation, provisioning, and policy enforcement. If you think in trust boundaries, federation patterns, and policy enforcement more than signals and scoring, this is your seat. Candidates considered for this role will be located in the San Francisco Bay Area. There will be an in-office expectation of 3x a week. The job Define and evolve the end-to-end IAM architecture spanning authentication, authorization, session management, and token lifecycle across consumer and enterprise contexts. Establish the trust boundaries, integration contracts, and platform primitives that make the secure path the default for every team consuming identity services. Own the  enterprise identity onboarding experience  for our nonprofit customers: repeatable, self-service SSO, SCIM provisioning, and multi-tenant trust patterns that scale without bespoke integration per partner. Architect  federation and provisioning patterns  (OIDC, SAML 2.0, SCIM) that hold up across a wide range of enterprise IdP configurations, from large institutions to small grassroots organizations. Make principled  build vs. integrate decisions  across vendor platforms (Descope, Auth0, Okta) and in-house systems, owning the tradeoffs, migration paths, and long-term cost of change. Design and operate  MFA orchestration and step-up authentication  flows, integrating risk signals from the Identity & Risk Intelligence engineer to make adaptive, confident auth decisions without adding unnecessary friction for the legitimate majority. Own the  consumer identity platform , including Descope CIAM, session management, passwordless authentication, and social login, balancing security against funnel conversion with a lean toward the enterprise and Pro surfaces where IAM complexity is highest. Establish  policy enforcement architecture  (PEP and PAP) and the contracts by which authorization decisions are reliably enforced at runtime across consumer and enterprise surfaces. Own the  IAM technical roadmap , prioritizing initiatives based on user impact, enterprise requirements, compliance obligations, and technical feasibility. Partner with  Identity & Risk Intelligence, Payments, Security, an