> Markdown version of [/jobs/ext/2723196-staff-software-engineer-identity-access-management](https://www.wearedevelopers.com/jobs/ext/2723196-staff-software-engineer-identity-access-management). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Staff Software Engineer (Identity & Access Management) - **Company:** GoFundMe Inc. - **Location:** New York, NY, United States (Remote available) - **Experience:** Expert - **Salary:** $233,500.0 - $321,200.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Microsoft Azure, Software as a Service, Cloud Computing, Identity and Access Management, OAuth, Open Source Technology, OpenID, PCI Data Security Standards, Ping (Networking Utility), Role-Based Access Control, Openid Connect, Security Assertion Markup Language (SAML), Session Management, Software Engineering, Okta, Customer Identity Access Management, Build Tools - **Published:** September 4, 2026 - **Apply:** https://startup.jobs/senior-staff-software-engineer-identity-access-management-gofundme-7898823 ## About the Role * 8+ years of software engineering experience, with significant time at senior, staff, or principal levels working on platform or infrastructure systems. * Deep, hands-on expertise with identity protocols and standards: OAuth 2.x, OpenID Connect, SAML 2.0, and SCIM. You can architect against these, not just integrate. * Track record of designing and shipping IAM or auth platforms that other engineering teams depend on in production at meaningful scale. * Demonstrated experience with enterprise identity at scale: SSO, SCIM provisioning, multi-tenant trust, IdP heterogeneity, and B2B platforms with a long tail of customer IdP configurations. * Experience architecting systems using federation standards, session and token management patterns, and well-defined trust boundaries, with an eye toward minimizing the cost of future change. * Strong security instincts: you threat-model as you design, understand credential risk and account takeover patterns, and build systems where the secure path is the easy path. * Strong observability and reliability skills: experience with monitoring, alerting, and incident response for mission-critical identity infrastructure., * Hands-on experience with commercial identity platforms (Descope, Auth0, Okta, Ping, or comparable) in production, including migration between providers. * Experience spanning both enterprise and consumer identity contexts, such as at fintech, SaaS, payments, or identity-forward companies. * Familiarity with advanced authorization models (RBAC, ABAC, ReBAC) and policy engines (OPA, Cedar), particularly the enforcement side. * Experience with compliance and audit requirements relevant to identity systems (SOC 2, PCI DSS, GDPR, CCPA) and data residency considerations. * Practical experience deploying and operating identity services on cloud infrastructure (AWS, GCP, or Azure) at scale. * Contributions to identity standards bodies, open-source identity projects, or published thought leadership in the IAM space., * Make an Impact: Be part of a mission-driven organization making a positive difference in millions of lives every year. ## Description * Define and evolve the end-to-end IAM architecture spanning authentication, authorization, session management, and token lifecycle across consumer and enterprise contexts. Establish the trust boundaries, integration contracts, and platform primitives that make the secure path the default for every team consuming identity services. * Own the enterprise identity onboarding experience for our nonprofit customers: repeatable, self-service SSO, SCIM provisioning, and multi-tenant trust patterns that scale without bespoke integration per partner. * Architect federation and provisioning patterns (OIDC, SAML 2.0, SCIM) that hold up across a wide range of enterprise IdP configurations, from large institutions to small grassroots organizations. * Make principled build vs. integrate decisions across vendor platforms (Descope, Auth0, Okta) and in-house systems, owning the tradeoffs, migration paths, and long-term cost of change. * Design and operate MFA orchestration and step-up authentication flows, integrating risk signals from the Identity & Risk Intelligence engineer to make adaptive, confident auth decisions without adding unnecessary friction for the legitimate majority. * Own the consumer identity platform, including Descope CIAM, session management, passwordless authentication, and social login, balancing security against funnel conversion with a lean toward the enterprise and Pro surfaces where IAM complexity is highest. * Establish policy enforcement architecture (PEP and PAP) and the contracts by which authorization decisions are reliably enforced at runtime across consumer and enterprise surfaces. * Own the IAM technical roadmap, prioritizing initiatives based on user impact, enterprise requirements, compliance obligations, and technical feasibility. * Partner with Identity & Risk Intelligence, Payments, Security, and Integrity as the IAM platform interface for the systems that depend on it. * Mentor engineers across the Identity team and the broader Platform Tribe, raising the bar on system design, security thinking, and operational rigor., Depending on your location, the General Data Protection Regulation (GDPR) or certain US privacy laws may regulate the way we manage the data of job applicants. Our full notice outlining how data will be processed as part of the application procedure for applicable locations is available here. By submitting your application, you are agreeing to our use and processing of your data as required. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Our GitOps approach for deploying an Identity Provider and an API Gateway in a SaaS company](https://www.wearedevelopers.com/videos/776-our-gitops-approach-for-deploying-an-identity-provider-and-an-api-gateway-in-a-saas-company) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Backstage in Practice: Offloading Developer Operational Work Through Platform Self-Service](https://www.wearedevelopers.com/videos/1922-backstage-in-practice-offloading-developer-operational-work-through-platform-self-service) ## Related Articles - [The Best X (Twitter) Accounts for Developers](https://www.wearedevelopers.com/magazine/294-the-best-x-twitter-accounts-for-developers) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [How Much FAANG Companies Actually Pay Software Engineers in 2025](https://www.wearedevelopers.com/magazine/230-how-much-faang-companies-actually-pay-software-engineers-in-2025) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Highest Paying Tech Companies in Europe](https://www.wearedevelopers.com/magazine/162-highest-paying-tech-companies-in-europe)