Identity & Access Management (IAM) Engineer, IT
Codeway · Barcelona · 2026-09-17
Sobre el puesto
ABOUT CODEWAY
Codeway builds category-leading consumer AI apps on mobile and web, at global scale.
600M+ downloads. 60+ apps. 400+ builders across Barcelona and İstanbul. Completely bootstrapped. No board. Profitable since year two.
Small teams move faster than big ones. But they need big resources to win at scale. Nobody starts from zero. The problem decides the solution, not us.
We turn category wins into six focused vertical companies: Wishlabs (AI Creativity), Wellture (Wellness), Learna (Education), Sparked (Media), Cosmic Jam (Entertainment), and Catalyst Apps (Utilities & Productivity). Each has full ownership and the depth to go further than anyone else in its space.
Codeway HQ powers them all. One platform. One team that finds and grows builders. One set of guardrails. Every idea born here starts with an unfair advantage: the platform, the people, and the profits of every product before it. That's the system.
Turns out you can do both.
Move like an indie. Hit like a giant.
POSITION
We're looking for an IAM Engineer to help run and improve the identity and access systems that every Codeway employee relies on. Okta is the front door to our environment, and you'll be hands-on with it every day: making sure people have the right access at the right time, keeping applications properly integrated, and building reliable processes that work quietly in the background.
You'll work across Okta, Google Workspace, Jamf, and the SaaS platforms our teams depend on. You'll onboard applications into SSO, maintain groups and entitlements, troubleshoot authentication and provisioning issues, and help keep our identity setup well-governed and reliable. A big part of the role will be looking at what's still being done manually and turning it into something automated, consistent, and dependable.
This is a hands-on role that combines identity engineering with day-to-day IT operations. You'll work the ticket queue, troubleshoot devices and applications, manage SaaS platforms, and be a visible technical presence in the Barcelona office. Roughly half of your time will focus on identity, access, and automation, with the other half covering IT support, endpoint management, and SaaS administration.
This is a hybrid role, based in our Barcelona office four days a week.
We welcome people with different backgrounds, experiences, and career paths. If you're excited about identity infrastructure, automation, and modern IT operations, we'd encourage you to apply even if you don't meet every qualification listed below. We care about what you can do, how you think, and your ability to learn as much as we care about what's already on your CV.
WHAT YOU'LL BE DOING?
IDENTITY & ACCESS MANAGEMENT
- Administer our Okta environment day to day, including user assignments, authentication policies, MFA, sign-on rules, and application access.
- Integrate new applications with SSO, working with application owners on SAML and OIDC configuration, attribute mapping, and testing.
- Build and maintain SCIM provisioning integrations so account lifecycles stay automated and consistent across our SaaS environment.
- Maintain our group, role, and entitlement model across Okta and Google Workspace, keeping access accurate and manageable as we scale.
- Support access reviews and least-privilege initiatives, including identifying and removing unused accounts, stale groups, and unnecessary permissions.
- Troubleshoot identity and access issues, including authentication, provisioning, MFA, and application access problems.
IT SUPPORT & EMPLOYEE LIFECYCLE
- Provide hands-on support to colleagues across identity, devices, connectivity, and SaaS, both in person in Barcelona and remotely for other locations.
- Work the IT support queue, resolving requests within agreed service levels and escalating issues that require deeper investigation.
- Set up, deploy, and troubleshoot laptops, peripherals, meeting room equipment, and other workplace technology.
- Run joiner, mover, and leaver processes, ensuring access is granted, changed, and revoked reliably and on time, while delivering a strong first-day experience for new joiners.
- Keep runbooks and internal documentation current, and identify recurring requests that can be turned into self-service, automation, or more repeatable processes.
ENDPOINT & SAAS ADMINISTRATION
- Support our macOS fleet through Jamf Pro, including enrollment, configuration profiles, policies, and application deployment.
- Administer business-critical SaaS platforms, including configuration, licensing, roles, permissions, and identity integrations.
- Help bring unmanaged applications and tools under central identity and access governance.
- Maintain accurate asset and inventory data across devices, accounts, applications, and licenses.
AUTOMATION & IMPROVEMENT
- Build automation for IT and identity workflows using scripting, APIs, and workflow tools.
- Develop integrations between identity, endpoint, ITSM, and SaaS platforms to reduce manual handoffs and improve reliability.
- Identify friction and recurring manual work in existing processes, and propose practical improvements.
- Contribute to identity, endpoint, and IT operations standards as our environment evolves.
- Document and share what you build, so that improvements become part of how the team operates.
WHAT YOU'LL BRING?
- Hands-on experience administering an identity provider in production, ideally Okta, including application assignments, authentication policies, MFA, and user lifecycle management.
- A solid understanding of identity fundamentals, including SSO, SAML, OIDC, SCIM, MFA, group and entitlement management, and least privilege.
- Experience providing IT support in a cloud-first environment, with the patience and communication skills to support colleagues with different levels of technical experience.
- Experience administering Google Workspace or a comparable…
Competencias solicitadas
- go
- python
- bash
- aws
- gcp
- google cloud
Tu próximo puesto ya está aquí.
Busca ofertas en directo de miles de empresas, guarda las que merecen una segunda mirada y deja que JobBob vigile el resto.