GoFundMe logo

Senior Staff Software Engineer, Identity & Risk Intelligence

GoFundMe
3 hours ago
Full-time
On-site
San Francisco, California, United States
Engineer

Want to help us help others? We’re hiring! 

GoFundMe is the world's most powerful community for good. Our community has raised more than $40 billion since 2010, connecting millions of donors, beneficiaries, and nonprofit partners on a single platform built for trust.

GoFundMe is hiring a Senior Staff Software Engineer, Identity & Risk Intelligence to anchor the intelligence side of our horizontal Identity Platform Engineering layer. You will set the technical direction for how GoFundMe recognizes, resolves, and trusts the people on its platform, and lead the engineering behind it.

Every donation is an act of trust, and earning that trust is an identity problem: recognizing returning users, building confidence over time, and applying friction only where it is warranted. This role owns that capability at platform scale, across both our consumer and enterprise platforms: progressive identity, login risk signals, device intelligence, and the identity confidence layer that teams across GoFundMe depend on for real-time trust decisions.

You will be one of three horizontal Identity Platform Engineers reporting to the Sr. Manager of Identity and Integrity Engineering, alongside an IAM engineer and a Policy and Data engineer, partnering with stakeholders across the company to identify needs and build the platform around identity resolution, the identity graph, and confidence. The IAM role owns access (federation, provisioning, policy enforcement); you own knowing who someone is and how much to trust them. If you think in visitor stitching, device intelligence, and identity graph problems more than access controls, this is your seat.

Candidates considered for this role will be located in the San Francisco Bay Area. There will be an in-office expectation of 3x a week.

The job

  • Build a progressive identity layer that defines how GoFundMe recognizes returning visitors, stitches anonymous device history to a person at signup or login, and raises identity confidence over time, from anonymous visitor to guest to known user.
  • Architect identity resolution and the identity graph: visitor stitching, account linking, and confidence-weighted models that power personalization, guest donor checkout prefill, and fraud prevention across our consumer and enterprise surfaces.
  • Build the behavioral signals and identity confidence scoring platform: the data products and APIs that IAM, Integrity, and Payments depend on for real-time trust and authorization decisions.
  • Shape login risk into adaptive experiences: turn risk signals (bot detection, identity-provider risk events, device intelligence, behavioral signals) into adaptive MFA and step-up authentication that protect against account takeover without adding friction for the legitimate majority.
  • Shape the login and recognition experience on our CIAM platforms, in partnership with the IAM engineer who anchors them: passwordless authentication, social login, and session decisions informed by recognition and risk, balancing security against funnel conversion across millions of interactions.
  • Design the policy decision and information layer (PDP and PIP) that informs IAM's step-up and session enforcement decisions and Integrity's account-level abuse actions.
  • Own the platform's approach to large-scale identity-based threats: bot activity, SMS fraud, credential stuffing, and account manipulation at scale. This is the emerging cloud security gap that sits between the Auth and Identity and Integrity teams, and closing it is the charter of this role.
  • Partner with Integrity, Payments, and Decision Science on identity signal use cases across their distinct needs: account-level trust and T&S feedback loops (Integrity), guest checkout recognition and device fingerprinting (Payments), and bot detection signal quality and experimentation support (Decision Science).
  • Own the identity and risk intelligence technical roadmap, prioritizing across product enablement (guest donor experience, identity unification, fraud reduction) and platform durability (signal quality, confidence calibration, model evaluation).

You

  • 8+ years of software engineering experience, with significant time at senior, staff, or principal levels working on identity, risk, fraud, or trust and safety platforms.
  • Track record of designing and shipping identity resolution, identity graph, behavioral signal, or risk scoring systems that other teams depend on in production.
  • Deep experience with the technical patterns that underlie this domain: device fingerprinting, visitor stitching, account linking, behavioral feature engineering, confidence calibration, and risk model integration.
  • Deep identity and CIAM platform experience at scale: auth, sessions, passwordless authentication, social login, and the engineering decisions that balance security against conversion.
  • Fluency with login risk and adaptive authentication, including risk scoring, step-up flows, and device signals, applied to user experience rather than detection alone.
  • Strong systems thinking about identity as a risk problem: you understand the difference between authenticating a user and being confident in their identity over time, and you are pragmatic about the friction-vs-security tradeoff and unit economics at scale.

Preferred

  • Background at a fintech, payments, marketplace, social, or trust and safety-forward company where identity, fraud, and risk were treated as a unified platform problem.
  • CIAM platform experience (Descope, Okta, Auth0, or comparable) including risk-based and adaptive auth models.
  • Familiarity with device fingerprint and risk vendors (Alloy, Fingerprint.js, ThreatMetrix) as input signals to a risk and identity confidence layer.
  • Experience with behavioral analytics and ML-adjacent systems, including feature stores, signal pipelines, and model serving infrastructure, even if you are not primarily an ML engineer.
  • Experience with compliance and regulatory framing around identity signals (KYC, BSA/AML adjacent, GDPR, CCPA), particularly where device or behavioral signals are involved as approved identifiers.
  • Public contributions, talks, or thought leadership in the identity, risk, fraud, or trust and safety space.