Bonterra, founded in 2021, operates what it calls a unified platform connecting nonprofits, foundations, corporations, and government agencies in the social impact space. The company positions itself as the second-largest and fastest-growing social good software company globally, powering more than 180,000 nonprofits and facilitating over $28 billion in annual fundraising. That's a significant attack surface: donor PII, financial transaction data, grant-making workflows, and the operational pipelines of mission-critical organizations.
The product stack is broad - CyberGrants, EveryAction, Network for Good, Social Solutions, OneCause, and DonorDrive are all integrated under the Bonterra umbrella. Each brings its own legacy codebase, authentication flows, and data models into a single platform. For security engineers, the challenge is real: you're not defending one application, you're securing an ecosystem of acquired products where integration seams, inconsistent trust boundaries, and high-value data converge.
The threat model is straightforward. Nonprofits and foundations are increasingly targeted for business email compromise, credential stuffing, and supply-chain attacks - not because they're glamorous targets, but because they handle real money and often lack mature security postures. Bonterra's platform sits in the middle of that transaction flow, making it both a high-value target and a leverage point for protecting an entire sector. The company's stated mission - increasing giving as a percentage of GDP from 2.5% to 3% by 2033 - implies continued scale, which means continued security investment.
The company culture is oriented around social impact, inspired by figures like Sir Ronald Cohen. If you're looking for a role where the data you protect directly enables billions in charitable giving, that's the pitch. The technical reality is a large, heterogeneous platform with real complexity and real stakes.






