Senior Staff Software Engineer (Identity & Access Management)
GoFundMe · San Francisco, United States
About The Role
Join GoFundMe as a Senior Staff Software Engineer for Identity Platform. In this role, you will be the technical leader driving the architecture, scalability, and reliability of our identity platform. Your work will directly impact how millions of people trust and interact with GoFundMe. You will define the end-to-end IAM architecture, own the enterprise identity onboarding experience, and make build vs. integrate decisions across vendor platforms and in-house systems. You will also design and operate MFA orchestration, own the consumer identity platform, establish policy enforcement architecture, and own the IAM technical roadmap. Additionally, you will mentor engineers across the Identity team and the broader Platform Tribe.
- Define and evolve the end-to-end IAM architecture spanning authentication, authorization, session management, and token lifecycle across consumer and enterprise contexts.
- Own the enterprise identity onboarding experience for our nonprofit customers: repeatable, self-service SSO, SCIM provisioning, and multi-tenant trust patterns that scale without bespoke integration per partner.
- Architect federation and provisioning patterns (OIDC, SAML 2.0, SCIM) that hold up across a wide range of enterprise IdP configurations, from large institutions to small grassroots organizations.
- Strong security instincts: you threat-model as you design, understand credential risk and account takeover patterns, and build systems where the secure path is the easy path
- Proficiency in relational database design and data modeling for identity systems, including schema evolution strategies for high-availability environments
- Deep, hands-on expertise with identity protocols and standards: OAuth 2.x, OpenID Connect, SAML 2.0, and SCIM
- 8+ years of software engineering experience, with significant time at senior, staff, or principal levels working on platform or infrastructure systems
- Demonstrated ability to lead projects from ambiguity through delivery, balancing technical depth with business context and keeping teams aligned across organizational boundaries
- Strong observability and reliability skills: experience with monitoring, alerting, and incident response for mission-critical identity infrastructure
- Track record of designing and shipping identity or auth platforms that other engineering teams depend on in production
- Experience architecting systems using federation standards, session/token management patterns, and well-defined trust boundaries, with an eye toward minimizing the cost of future change
- Hands-on experience with commercial identity platforms (Descope, Auth0/Okta, Ping, or comparable) in production, including migration between providers
- Experience spanning both enterprise and consumer identity contexts, such as at fintech, SaaS, payments, or identity-forward companies
- Familiarity with advanced authorization models: RBAC, ABAC, ReBAC, or policy engines such as OPA/Cedar
- Experience with compliance and audit requirements relevant to identity systems (SOC 2, PCI DSS, GDPR, CCPA) and data residency considerations
- Practical experience deploying and operating identity services on cloud infrastructure (AWS, GCP, or Azure) at scale
- Contributions to identity standards bodies, open-source identity projects, or published thought leadership in the IAM space
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring