gofundme
Senior Staff Software Engineer (Identity & Access Management)
At a Glance
- Location
- San Francisco, California, United States
- Compensation
- or this full-time position is $262,800 - $321,200, [ Include for sales roles onl
- Posted
- 2026-04-01T12:57:19-04:00
Key Requirements
Required Skills
Domain Knowledge
- Cloud
- Regulatory
- SaaS
Requirements
Hands-on experience with commercial identity platforms (Descope, Auth0/Okta, Ping, or comparable) in production, including migration between providers.
Experience spanning both enterprise and consumer identity contexts, such as at fintech, SaaS, payments, or identity-forward companies.
Familiarity with advanced authorization models: RBAC, ABAC, ReBAC, or policy engines such as OPA/Cedar.
Experience with compliance and audit requirements relevant to identity systems (SOC 2, PCI DSS, GDPR, CCPA) and data residency considerations.
Practical experience deploying and operating identity services on cloud infrastructure (AWS, GCP, or Azure) at scale.
Contributions to identity standards bodies, open-source identity projects, or published thought leadership in the IAM space.
Compensation & Benefits
Holistic Support
: Enjoy financial assistance for things like hybrid work, family planning, along with generous parental leave, flexible time-off policies, and mental health and wellness resources to support your overall well-being.
Growth Opportunities
: Participate in learning, development, and recognition programs to help you thrive and grow.
Commitment to DEI
: Contribute to diversity, equity, and inclusion through ongoing initiatives and employee resource groups.
Responsibilities
Define and evolve the end-to-end identity architecture spanning authentication, authorization, session management, and token lifecycle across consumer and enterprise contexts.
Establish trust boundaries, integration contracts, and platform primitives that make the secure path the default path for every team consuming identity services.
Make principled build-vs-integrate decisions across vendor (e.g., Descope, Auth0, Okta) and in-house systems, owning the tradeoffs and migration paths.
Design repeatable, self-service enterprise identity onboarding (SSO, SCIM provisioning, multi-tenant trust) so that each new partnership does not require bespoke integration.
Architect federation and provisioning patterns that support GoFundMe’s growing enterprise and nonprofit partnerships.
Own the consumer identity lifecycle including account continuity, progressive trust, confidence scoring, and anonymous-to-authenticated transitions.
About the Company
We’re proud to partner with
GoFundMe.org
, an independent public charity, to extend the reach and impact of our generous community, while helping drive critical social change. You can learn more about GoFundMe.org’s activities and impact in their
FY ‘25 annual report
.
Our