gofundme

Senior Staff Software Engineer (Identity & Access Management)

Apply Now

At a Glance

Location
San Francisco, California, United States
Compensation
or this full-time position is $262,800 - $321,200, [ Include for sales roles onl
Posted
2026-04-01T12:57:19-04:00

Key Requirements

Required Skills

AWSAzureGCP

Domain Knowledge

  • Cloud
  • Regulatory
  • SaaS

Requirements

Hands-on experience with commercial identity platforms (Descope, Auth0/Okta, Ping, or comparable) in production, including migration between providers.

Experience spanning both enterprise and consumer identity contexts, such as at fintech, SaaS, payments, or identity-forward companies.

Familiarity with advanced authorization models: RBAC, ABAC, ReBAC, or policy engines such as OPA/Cedar.

Experience with compliance and audit requirements relevant to identity systems (SOC 2, PCI DSS, GDPR, CCPA) and data residency considerations.

Practical experience deploying and operating identity services on cloud infrastructure (AWS, GCP, or Azure) at scale.

Contributions to identity standards bodies, open-source identity projects, or published thought leadership in the IAM space.

Compensation & Benefits

Holistic Support

: Enjoy financial assistance for things like hybrid work, family planning, along with generous parental leave, flexible time-off policies, and mental health and wellness resources to support your overall well-being.

Growth Opportunities

: Participate in learning, development, and recognition programs to help you thrive and grow.

Commitment to DEI

: Contribute to diversity, equity, and inclusion through ongoing initiatives and employee resource groups.

Responsibilities

Define and evolve the end-to-end identity architecture spanning authentication, authorization, session management, and token lifecycle across consumer and enterprise contexts.

Establish trust boundaries, integration contracts, and platform primitives that make the secure path the default path for every team consuming identity services.

Make principled build-vs-integrate decisions across vendor (e.g., Descope, Auth0, Okta) and in-house systems, owning the tradeoffs and migration paths.

Design repeatable, self-service enterprise identity onboarding (SSO, SCIM provisioning, multi-tenant trust) so that each new partnership does not require bespoke integration.

Architect federation and provisioning patterns that support GoFundMe’s growing enterprise and nonprofit partnerships.

Own the consumer identity lifecycle including account continuity, progressive trust, confidence scoring, and anonymous-to-authenticated transitions.

About the Company

We’re proud to partner with

GoFundMe.org

, an independent public charity, to extend the reach and impact of our generous community, while helping drive critical social change. You can learn more about GoFundMe.org’s activities and impact in their

FY ‘25 annual report

.

Our