GoFundMe
Senior Security Engineer
Job Summary
The Senior Security Engineer role involves conducting application security assessments, collaborating with engineering teams on architecture and secure coding practices, and managing vulnerabilities and security incidents. The position requires experience with industry standards such as OWASP Top 10, mobile and cloud security, and secure code review in languages like PHP, Python, Kotlin, JavaScript, and TypeScript. The role emphasizes building a secure platform for giving while supporting a mission-driven organization with comprehensive benefits. It offers opportunities for growth, training, and contributing to community and diversity initiatives.
Required Skills
Benefits
Job Description
Want to help us help others? We’re hiring!
GoFundMe is the world’s most powerful community for good, dedicated to helping people help each other. By uniting individuals and nonprofits in one place, GoFundMe makes it easy and safe for people to ask for help and support causes—for themselves and each other. Together, our community has raised more than $40 billion since 2010.
Join us! The GoFundMe team is searching for our next Senior Security Engineer to help build a secure platform for giving.
The Job
- Conduct regular application security assessments with team members
- Collaborate with engineering teams on architecture decisions and review pull requests
- Help handle application vulnerability reports received through third-party sources, review, prioritize, and work with the relevant engineering teams to remediate them
- Assist with the delivery of secure coding training
- Participate in security initiatives from brainstorming sessions to implementation
- Work with incident response teams and participate in post-mortem investigation of security incidents
- Participate in on-call rotation
You
- 3+ years designing and building secure systems with engineering teams
- Experience with OWASP Top 10 and other industry standards
- Experience with mobile application security and security testing
- Experience with securing cloud infrastructure
- Understanding of web application architecture and design principles
- Prior experience working in a regulated environment
- Experience in secure code review, including basic skills in languages such as: PHP, Python, Kotlin, JavaScript, and TypeScript.
- Excellent written and verbal communication skills
Why you’ll love it here
- Make an Impact: Be part of a mission-driven organization making a positive difference in millions of lives every year.
- Innovative Environment: Work with a diverse, passionate, and talented team in a fast-paced, forward-thinking atmosphere.
- Collaborative Team: Join a fun and collaborative team that works hard and celebrates success together.
- Competitive Benefits: Enjoy competitive pay and comprehensive healthcare benefits.
- Holistic Support: Enjoy financial assistance for things like hybrid work, family planning, along with generous parental leave, flexible time-off policies, and mental health and wellness resources to support your overall well-being.
- Growth Opportunities: Participate in learning, development, and recognition programs to help you thrive and grow.
- Commitment to DEI: Contribute to diversity, equity, and inclusion through ongoing initiatives and employee resource groups.
- Community Engagement: Make a difference through our volunteering and Gives Back programs.
We live by our core values: impatient to be great, find a way, earn trust every day, fueled by purpose. Be a part of something bigger with us!
GoFundMe is proud to be an equal opportunity employer that actively pursues candidates of diverse backgrounds and experiences. We do not discriminate on the basis of race, color, religion, ethnicity, nationality or national origin, sex, sexual orientation, gender, gender identity or expression, pregnancy status, marital status, age, medical condition, mental or physical disability, or military or veteran status.
The total annual salary for this full-time position is $125,000 - $187,000 + equity + benefits. As this is a remote position, the salary range was determined by role, level, and possible location across the US. Individual pay is determined by work location and additional factors including job-related skills, experience, and relevant education or training. Your recruiter can share more about the specific salary range based on your location during the hiring process.
If you require a reasonable accommodation to complete a job application or a job interview or to otherwise participate in the hiring process, please contact us at [email protected].
Global Data Privacy Notice for Job Candidates and Applicants:
Depending on your location, the General Data Protection Regulation (GDPR) or certain US privacy laws may regulate the way we manage the data of job applicants. Our full notice outlining how data will be processed as part of the application procedure for applicable locations is available here. By submitting your application, you are agreeing to our use and processing of your data as required.
Learn more about GoFundMe:
We’re proud to partner with GoFundMe.org, an independent public charity, to extend the reach and impact of our generous community, while helping drive critical social change. You can learn more about GoFundMe.org’s activities and impact in their FY ‘24 annual report.
Our annual “Year in Help” report reflects our community’s impact in advancing our mission of helping people help each other.
For recent company news and announcements, visit our Newsroom.
_____________
Notice to Applicants for Jobs Located in NYC or Remote Jobs Associated With Office in NYC Only
We use Covey as part of our hiring and/or promotional process for jobs in NYC and certain features may qualify it as an AEDT in NYC. As part of the hiring and/or promotion process, we provide Covey with job requirements and candidate submitted applications. We began using Covey Scout for Inbound May 1, 2025.
The Covey tool has been reviewed by an independent auditor. Results of the audit may be viewed here: Covey
GoFundMe
Start your fundraiser in minutes with tools to help you succeed. GoFundMe is the global leader in crowdfunding, trusted by 100+ million people.
See more jobsSafe Remote Job Search Tips
Verify Employer Thoroughly
Research the company's identity thoroughly before applying. Check for a professional website with contacts, active social media, and LinkedIn profiles. Verify details across platforms and look for reviews on Glassdoor or Trustpilot to confirm legitimacy.
Never Pay to Get a Job
Legitimate employers never require payment for applications, training, background checks, or equipment. Always reject upfront payment requests or demands for bank details, even if they claim it's for purchasing necessary work gear on your behalf.
Safeguard Your Personal Information
Protect sensitive data like SSN, bank details, or ID copies. Share this only after accepting a formal, written job offer. Ensure it's submitted via a secure company system or portal, never through insecure channels like standard email attachments.
Scrutinize Communication & Interviews
Watch for communication red flags: poor grammar, generic emails (@gmail), vague details, or undue pressure. Be highly suspicious of interviews held only via text or chat apps; legitimate companies typically use video or phone calls.
Beware of Unrealistic Offers
If an offer's salary or benefits seem unrealistically high for the work involved, be cautious. Research standard pay for similar roles. Offers that appear 'too good to be true' are often scams designed to lure you into providing information or payment.
Insist on a Formal Contract
Always secure and review a formal, written job offer or employment contract before starting work or sharing final personal details. Ensure it clearly defines your role, compensation, key terms, and conditions to avoid misunderstandings or scams.