Senior Software Engineer, Privacy & Data Governance
Want to help us help others? We're hiring!
GoFundMe is the world’s most powerful community for good, dedicated to helping people help each other. By uniting individuals and nonprofits in one place, GoFundMe makes it easy and safe for people to ask for help and support causes—for themselves and each other. Together, our community has raised more than $40 billion since 2010.
Join us! The GoFundMe team is searching for our next Senior Software Engineer, Privacy & Data Governance to join a growing team building and operating the technical infrastructure that ensures GoFundMe honors its data privacy and information management commitments at scale.
You will work across engineering, privacy, and compliance, partnering with Legal & Privacy to translate regulatory requirements into durable, production-grade services. That means building the systems that execute data subject requests, enforce data classification across our data ecosystem, and propagate consent signals from capture through every downstream system.
If you enjoy building reliable, auditable systems under real regulatory pressure and getting the edge cases right, this role is for you.
This is a hybrid position. Candidates considered for this role will be located in Buenos Aires, Argentina.
The Job
- Own Data Subject Request pipeline reliability end-to-end: When our DSR orchestrator reports a deletion failure or a pre-flight check flags an inconsistency, you investigate and resolve it [on a shared rotation / as part of normal triage, to confirm]. You'll build DSR handling pipelines that are auditable, resumable, and idempotent, and that can retry safely from an inconsistent state and hold up against third-party API timeouts, partial writes, and stalled event consumers.
- Own access, deletion, and objection processes at the data layer: Maintain and extend the scripts and workflows that carry out individual-level privacy requests across our data warehouse, handling edge cases like legal holds, financial data exemptions, and users who appear across multiple systems under different identifiers.
- Build the systems that classify and protect personal data: Classify and tag personal and sensitive data, and enforce sensitivity tiers across our data catalog. Apply the right redaction method for the situation (e.g., hard delete, nullify, pseudonymize), using approved tokenization and encryption services where policy requires them.
- Drive consent signal propagation: Make sure consent state travels correctly from capture (analytics, retargeting, model training opt-outs, email subscription statuses) through tag managers, event pipelines, and downstream systems such as ad platforms, CDPs, and the data warehouse. Identify and close gaps where a signal is captured but doesn't reach a downstream system, or isn't honored end-to-end across web, mobile, email, and server-to-server channels. Help design and build a centralized consent source of truth.
- Partner on consent management platform (CMP) operations: Work with Pro PMs and Engineering on release management, QA, and production troubleshooting for our CMP across Consumer and Pro instances.
- Build privacy in early: Turn privacy requirements into concrete engineering decisions that support Privacy by Design. Bring them into product development and security engineering reviews, and know when to escalate together with Legal & Privacy.
- Produce technical compliance evidence: Generate the coverage reports, logs, and documentation that support internal privacy-compliance reviews and external audits.
- Use AI to increase engineering impact: Integrate AI-assisted tools and coding agents into your day-to-day workflow to deliver more than traditional development practices alone would allow. Use them to accelerate prototyping, implementation, test generation, debugging, data investigation, documentation, and repetitive engineering work, while holding to our standards for accuracy, maintainability, security, and code review.
You
We care most about strong engineering fundamentals, the ability to learn a new domain quickly, and the judgment to partner with Legal, Privacy, and engineering teams and drive technical work to completion.
- Senior engineering experience with hands-on privacy exposure: 5+ years building and operating production backend or distributed systems, including meaningful, repeated work on privacy or compliance systems, such as DSR or deletion flows, consent handling, data classification, or retention.
- Strong programming: Fluency in a general-purpose language (Python, Java, Kotlin, Go, or similar) for ETL, redaction scripts, pre-flight checks, and coverage reporting, including integrating with external vendor REST APIs (authentication, error handling, rate limiting).
- Reliable, long-running workflows: Experience designing or maintaining multi-step pipelines with independent failure modes, including checkpointing, resumability, and idempotent retries.Incident debugging and ownership: Experience driving a real incident to resolution independently, including one where a pipeline left data partially processed and you reconstructed ground truth from logs, database state, or audit trails.Operating services: Comfort deploying and running services in a containerized environment (Kubernetes basics: deploy, read logs, diagnose a failing pod), with observability and sound handling of secrets and credentials.
- Working knowledge of data stores: Comfort reading and writing SQL and working with data warehouses and databases well enough to build and validate deletion, redaction, and reporting logic.
- Requirements into engineering work: Ability to take a privacy requirement, identify the concrete engineering work it creates, and push back when something is infeasible or counterproductive.
- Clear communication and partnership: Ability to explain regulatory, technical, and implementation tradeoffs to engineering and non-engineering stakeholders, and to partner effectively with Legal & Privacy, the Privacy Program Manager, and owning teams when DSR or consent coverage gaps surface outside Data Platform.
- AI fluency: Working fluency with AI assistants, coding agents, and agentic workflows, with examples of using them to improve the speed, quality, or scope of your delivery.
- Experience in several of the following privacy-related areas (you don't need all of them):
- Working familiarity with data protection law such as Argentina's Ley 25.326, GDPR/UK GDPR, and CCPA, and how it shapes system design: redaction strategy, retention (legal hold, regulatory minimums, storage limitation), and re-identification risk
- Event-driven systems with Kafka or equivalent, including safe handling of at-least-once delivery and propagation of deletion signals downstream
- Individual-level deletion or redaction across large or distributed data stores, including the tradeoffs between hard delete, nullification, and masking
- Defining sensitivity tiers and enforcing PII tagging across data stores or a data catalog
- Enforcing consent in backend systems and data flows, not only in the browser
- Integrating third-party privacy platforms, DSR orchestrators, or consent management platforms, including release management, QA, and production troubleshooting
Preferred
- Experience in a regulated industry (fintech, healthcare, banking) where audit trails and compliance evidence were hard production requirements
- Privacy-enhancing techniques in production, such as pseudonymization, data minimization, differential privacy, or synthetic data
- Google Consent Mode and server-side tag management
- Role-based access control and column-level masking policies in a warehouse
- Familiarity with data catalog tooling (Collate, DataHub, Atlan, or similar), dbt, or data lineage
- Direct experience with Snowflake, Kotlin/JVM, Transcend, DataGrail, or OneTrust
- Frontend experience in TypeScript or JavaScript for instrumenting consent UI or debugging client-side privacy tooling
- A track record of building well-documented systems and raising the bar for how privacy infrastructure is built and operated
Why you’ll love it here
- Make an Impact: Be part of a mission-driven organization making a positive difference in millions of lives every year.
- Innovative Environment: Work with a diverse, passionate, and talented team in a fast-paced, forward-thinking atmosphere.
- Collaborative Team: Join a fun and collaborative team that works hard and celebrates success together.
- Competitive Benefits: Enjoy competitive pay and comprehensive healthcare benefits.
- Holistic Support: Enjoy financial assistance for things like hybrid work, family planning, along with generous parental leave, flexible time-off policies, and mental health and wellness resources to support your overall well-being.
- Growth Opportunities: Participate in learning, development, and recognition programs to help you thrive and grow.
- Commitment to DEI: Contribute to diversity, equity, and inclusion through ongoing initiatives and employee resource groups.
- Community Engagement: Make a difference through our volunteering and Gives Back programs.
We live by our core values: impatient to be great, find a way, earn trust every day, fueled by purpose. Be a part of something bigger with us!
GoFundMe is proud to be an equal opportunity employer that actively pursues candidates of diverse backgrounds and experiences. We do not discriminate on the basis of race, color, religion, ethnicity, nationality or national origin, sex, sexual orientation, gender, gender identity or expression, pregnancy status, marital status, age, medical condition, mental or physical disability, or military or veteran status.
If you require a reasonable accommodation to complete a job application or a job interview or to otherwise participate in the hiring process, please contact us at accommodationrequests@gofundme.com.
Global Data Privacy Notice for Job Candidates and Applicants:
Depending on your location, the General Data Protection Regulation (GDPR) or certain US privacy laws may regulate the way we manage the data of job applicants. Our full notice outlining how data will be processed as part of the application procedure for applicable locations is available here. By submitting your application, you are agreeing to our use and processing of your data as required.
Learn more about GoFundMe:
We’re proud to partner with GoFundMe.org, an independent public charity, to extend the reach and impact of our generous community, while helping drive critical social change. You can learn more about GoFundMe.org’s activities and impact in their FY ‘26 annual report.
Our annual “Year in Help” report reflects our community’s impact in advancing our mission of helping people help each other.
For recent company news and announcements, visit our Newsroom.