Senior Staff Software Engineer
Job description
About the role
Senior Staff Software Engineer, Identity & Access Management
GoFundMe is the world's most powerful community for good. Since 2010, our community has raised over $40 billion, connecting millions of donors, beneficiaries, and nonprofit partners on a single platform built for trust. We are currently seeking a Senior Staff Software Engineer, Identity & Access Management to define the architecture, evolution, and reliability of our IAM platform. This role is foundational; you will shape how millions authenticate, how nonprofit partners federate, and how engineering teams consume identity with confidence.
You will be one of three horizontal Identity Platform Engineers, reporting to the Sr. Manager of Identity and Integrity Engineering. You will partner alongside an Identity & Risk Intelligence engineer and a Policy and Data engineer. Together, you will work cross-functionally to identify needs and build the access platform that every surface consumes. The Identity & Risk Intelligence function focuses on understanding who someone is and how much to trust them; your responsibility is access, encompassing federation, provisioning, and policy enforcement. If your strength lies in trust boundaries, federation patterns, and policy enforcement rather than signals and scoring, this is your role.
Candidates for this role must be located in the San Francisco Bay Area and able to work 3 days per week in the office.
The role
You will define and evolve the end-to-end IAM architecture that spans authentication, authorization, session management, and token lifecycle for both our consumer and Pro surfaces. You will establish the trust boundaries, integration contracts, and platform primitives that make the secure path the default for every team consuming identity services.
You will own the enterprise identity onboarding experience for nonprofit customers. This means creating a repeatable, self-service journey that includes SSO, provisioning, and multi-tenant trust patterns capable of scaling without bespoke integration for each partner. You will architect federation and provisioning patterns using OIDC, SAML 2.0, and SCIM that remain robust across a wide range of enterprise IdP configurations, from large institutions to small grassroots organizations.
You will make build vs. integrate decisions across vendor platforms such as Descope and Auth0, as well as Okta and internal systems. This ownership includes managing tradeoffs, migration paths, and the long-term cost of change. You will design and operate MFA orchestration and step-up authentication flows, integrating risk signals from the Identity & Risk Intelligence role to enable adaptive, confident authentication without adding unnecessary friction for legitimate users.
You will own the consumer identity platform, including Descope CIAM, session management, passwordless authentication, and social login. This work balances security against funnel conversion, with a lean toward the enterprise and Pro surfaces where IAM complexity is highest. You will establish policy enforcement architecture, including PEP and PAP, and the contracts by which authorization decisions are reliably enforced at runtime across consumer and enterprise surfaces.
You will own the IAM technical roadmap, prioritizing initiatives based on user impact, enterprise requirements, compliance obligations, and technical feasibility. You will partner with Identity & Risk Intelligence, Payments, Security, and Integrity teams as the IAM platform interface for the systems that depend on it. You will also mentor engineers across the Identity team and the broader Platform Tribe, raising the bar on system design, security thinking, and operational rigor.
Requirements
You bring 3-5 years of experience building and operating identity and access platforms at scale. You hold deep knowledge of federation, provisioning, MFA orchestration, session management, and policy enforcement patterns. You can design secure identity flows that serve both consumer simplicity and enterprise complexity across many IdP configurations. You communicate clearly with stakeholders to align on architecture, tradeoffs, and long-term platform strategy.
Nice to have
Experience with Descope, Auth0, Okta, or similar CIAM and federation platforms.
Skills & tools
Go, Java, Kotlin, Auth0, Descope, Okta, OIDC, SAML, SCIM, JWT, OAuth, OpenID, PEP, PAP, CIAM.
Practical notes
Please What you'll do