Senior Staff Software Engineer
GoFundMeUSA3w ago$233,500 - $321,200
Job description
About the role
GoFundMe is looking for a Senior Staff Software Engineer to lead the Identity and Access Management platform that underpins authentication and authorization for millions of users. You will shape how donors, organizers, nonprofits, and enterprise partners securely access the platform. This role spans both consumer and enterprise IAM, covering federation, provisioning, MFA orchestration, session management, and policy enforcement.
Key facts
What you'll do
- Shape and maintain the full IAM architecture including authentication, authorization, sessions, and token lifecycle for consumer and enterprise use cases
- Build a repeatable, self-service enterprise identity onboarding experience for nonprofit customers, including SSO and SCIM provisioning with multi-tenant trust patterns
- Design federation and provisioning approaches using OIDC, SAML 2.0, and SCIM that accommodate diverse enterprise IdP setups
- Make informed decisions on building in-house versus integrating vendor platforms such as Descope, Auth0, or Okta, accounting for migration paths and long-term costs
- Architect MFA orchestration and step-up authentication flows, incorporating risk signals for adaptive decisions that minimize friction for legitimate users
- Manage the consumer identity platform including Descope CIAM, passwordless authentication, social login, and session handling
- Establish policy enforcement architecture (PEP and PAP) with clear contracts for runtime authorization across all surfaces
- Own the IAM technical roadmap, balancing user impact, enterprise needs, compliance, and feasibility
- Collaborate with Identity & Risk Intelligence, Payments, Security, and Integrity teams as the primary IAM interface
- Mentor engineers across the Identity team and broader Platform Tribe on system design, security practices, and operational standards
Requirements
- 8+ years of software engineering experience, with substantial time at senior, staff, or principal level on platform or infrastructure systems
- Deep hands-on knowledge of identity protocols: OAuth 2.x, OpenID Connect, SAML 2.0, and SCIM, with ability to architect against these standards
- Proven track record designing and delivering IAM or auth platforms used by other engineering teams at meaningful scale
- Experience with enterprise identity at scale: SSO, SCIM provisioning, multi-tenant trust, IdP heterogeneity, and B2B platforms with varied customer IdP configurations
- Ability to architect systems using federation standards, session and token management patterns, and well-defined trust boundaries while minimizing future change costs
- Strong security instincts with experience in threat modeling, understanding credential risk and account takeover patterns, and building systems where secure defaults are easy
- Solid observability and reliability skills including monitoring, alerting, and incident response for critical identity infrastructure
Nice to have
- Hands-on production experience with commercial identity platforms such as Descope, Auth0, Okta, or Ping, including provider migrations
- Background spanning both enterprise and consumer identity contexts, such as at fintech, SaaS, payments, or identity-focused companies
- Familiarity with advanced authorization models (RBAC, ABAC, ReBAC) and policy engines like OPA or Cedar, particularly enforcement aspects
- Experience with compliance and audit requirements for identity systems including SOC 2, PCI DSS, GDPR, CCPA, and data residency considerations
- Practical experience deploying and operating identity services on AWS, GCP, or Azure at scale
- Contributions to identity standards bodies, open-source identity projects, or published work in the IAM space
Skills & tools
- OAuth 2.x, OpenID Connect, SAML 2.0, SCIM
- Descope, Auth0, Okta, Ping
- MFA orchestration, step-up authentication, passwordless authentication, social login
- Policy engines: OPA, Cedar
- Authorization models: RBAC, ABAC, ReBAC
- Cloud platforms: AWS, GCP, Azure
- Monitoring, alerting, incident response for identity infrastructure
Practical notes
- Benefits include healthcare, dental, vision, life insurance, and 401(k)
- Additional support for hybrid work, family planning, parental leave, flexible time off, and mental health resources
- Reasonable accommodation requests can be sent to accommodationrequests@gofundme.com
- NYC applicants: Metaview is used as part of the hiring process; independent audit results are available