ForgeApply
Try it free

ForgeApply · Job listing

Senior Staff Software Engineer (Identity & Access Management)

Gofundme

San Francisco, CA, US$234k – $321konsite

Apply in about a minute — without sacrificing quality.

ForgeApply autofills this application and tailors your resume to this exact posting. You review everything before it's sent. Free trial, no card required.

About this role

Want to help us help others? We’re hiring!

GoFundMe is the world's most powerful community for good, dedicated to helping people help each other. By uniting individuals and nonprofits in one place, GoFundMe makes it easy and safe for people to ask for help and support causes, for themselves and each other. Together, our community has raised more than $40 billion since 2010.

Join us! GoFundMe is hiring a Senior Staff Software Engineer, Identity & Access Management to lead the architecture, evolution, and reliability of our IAM platform. This is the foundational layer that every product team, enterprise customer, and internal service builds on. Your work will shape how millions of people authenticate, how enterprise nonprofit partners federate into GoFundMe, and how engineering teams across the company consume identity with confidence.

GoFundMe serves a uniquely broad surface area: consumer donors and recipients on one side, and a long tail of nonprofit partners on the other, ranging from small grassroots organizations to some of the largest charitable institutions in the world. That breadth, plus the merger history of our enterprise and consumer stacks, makes IAM both a core platform problem and a meaningful enterprise-grade challenge. You will set the technical direction for how those worlds converge into one secure, self-service, well-instrumented platform.

This role is one of three horizontal Identity Platform Engineers reporting to the Sr. Manager of Identity and Integrity Engineering. You will work alongside a Consumer Identity and Risk Signals engineer and a Policy and Data engineer to build the cross-cutting capabilities our product and operational stakeholders increasingly depend on. Your primary focus is enterprise and Pro identity: federation, provisioning, MFA orchestration, and policy enforcement.

The job

• Define and evolve the end-to-end IAM architecture spanning authentication, authorization, session management, and token lifecycle across consumer and enterprise contexts. Establish the trust boundaries, integration contracts, and platform primitives that make the secure path the default for every team consuming identity services.

• Own the enterprise identity onboarding experience for our nonprofit customers: repeatable, self-service SSO, SCIM provisioning, and multi-tenant trust patterns that scale without bespoke integration per partner.

• Architect federation and provisioning patterns (OIDC, SAML 2.0, SCIM) that hold up across a wide range of enterprise IdP configurations, from large institutions to small grassroots organizations.

• Make principled build vs. integrate decisions across vendor platforms (Descope, Auth0, Okta) and in-house systems, owning the tradeoffs, migration paths, and long-term cost of change.

• Design and operate MFA orchestration and step-up authentication flows, integrating risk signals from the Consumer Identity and Risk Signals engineer to make adaptive, confident auth decisions without adding unnecessary friction for the legitimate majority.

• Own the consumer identity platform , including Descope CIAM, session management, passwordless authentication, and social login, balancing security against funnel conversion with a lean toward the enterprise and Pro surfaces where IAM complexity is highest.

• Establish policy enforcement architecture (PEP and PAP) and the contracts by which authorization decisions are reliably enforced at runtime across consumer and enterprise surfaces.

• Own the IAM technical roadmap , prioritizing initiatives based on user impact, enterprise requirements, compliance obligations, and technical feasibility.

• Partner with Consumer Identity and Risk Signals, Payments, Security, and Integrity as the IAM platform interface for the systems that depend on it.

• Mentor engineers across the Identity team and the broader Platform Tribe, raising the bar on system design, security thinking, and operational rigor.

You

• 8+ years of software engineering experience, with significant time at senior, staff, or principal levels working on platform or infrastructure systems.

• Deep, hands-on expertise with identity protocols and standards : OAuth 2.x, OpenID Connect, SAML 2.0, and SCIM. You can architect against these, not just integrate.

• Track record of designing and shipping IAM or auth platforms that other engineering teams depend on in production at meaningful scale.

• Demonstrated experience with enterprise identity at scale : SSO, SCIM provisioning, multi-tenant trust, IdP heterogeneity, and B2B platforms with a long tail of customer IdP configurations.

• Experience architecting systems using federation standards, session and token management patterns, and well-defined trust boundaries , with an eye toward minimizing the cost of future change.

• Strong security instincts : you threat-model as you design, understand credential risk and account takeover patterns, and build systems where the secure path is the easy path.

• Strong observability and reliability skills : experience with monitoring, alerting, and incident response for mission-critical identity infrastructure.

Preferred

• Hands-on experience with commercial identity platforms ( Descope, Auth0, Okta, Ping , or comparable) in production, including migration between providers.

• Experience spanning both enterprise and consumer identity contexts , such as at fintech, SaaS, payments, or identity-forward companies.

• Familiarity with advanced authorization models ( RBAC, ABAC, ReBAC ) and policy engines (OPA, Cedar), particularly the enforcement side.

• Experience with compliance and audit requirements relevant to identity systems (SOC 2, PCI DSS, GDPR, CCPA) and data residency considerations.

• Practical experience deploying and operating identity services on cloud infrastructure (AWS, GCP, or Azure) at scale.

• Contributions to identity standards bodies, open-source identity projects, or published thought leadership in the IAM space.

Why you’ll lo

Salary insight

The midpoint of this range ($277k) is about 37% above the median disclosed salary for San Francisco roles listed on ForgeApply ($203k across 6,317 jobs).

See full Software Engineer salary data for San Francisco

Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.

Ready to apply to Gofundme?

Apply in about a minute

Similar jobs

More like this: Software Engineer Jobs · Software Engineer Jobs in San Francisco · More jobs at Gofundme · Browse all jobs