Identity & Access Management (IAM) Engineer, IT

Codeway

Barcelona

Híbrido

EUR 55.000 - 75.000

Jornada completa

Hace 3 días
Sé de los primeros/as/es en solicitar esta vacante
Generador de candidaturas

Destaca para este puesto: genera un currículum y una carta de presentación adaptados en cuestión de un minuto.

Supera los filtros ATS

Ventajas ofrecidas por este puesto de trabajo

Health Benefits
Meal Compensation
Top-Notch Office
Flexible Schedule
English Course Support

Descripción de la vacante

Codeway is seeking an IAM Engineer to manage identity and access systems for a fast-growing suite of apps. You will leverage Okta as the front door to our environment, ensuring correct access, reliable integrations, and automated processes that scale across SaaS platforms.

You'll work across Okta, Google Workspace, Jamf, and SaaS tools, turning manual tasks into automated workflows while supporting IT operations in our Barcelona office.

Formación

  • Hands-on experience with identity providers (ideally Okta) including assignments, MFA, and lifecycle management.
  • Strong understanding of SSO, SAML, OIDC, SCIM, MFA, and least-privilege access.

Responsabilidades

  • Administer Okta and verify authentication policies, MFA, and user lifecycle.
  • Integrate new apps with SSO (SAML/OIDC), map attributes, and test provisioning.
  • Maintain SCIM provisioning to automate account lifecycles across SaaS.
  • Manage groups, roles, and entitlements in Okta and Google Workspace.
  • Support joiners/movers/leavers and streamline access governance.

Descripción del empleo

ABOUT CODEWAY

Codeway builds category-leading consumer AI apps on mobile and web, at global scale.

600M+ downloads. 60+ apps. 400+ builders across Barcelona and İstanbul. Completely bootstrapped. No board. Profitable since year two.

Small teams move faster than big ones. But they need big resources to win at scale. Nobody starts from zero. The problem decides the solution, not us.

We turn category wins into six focused vertical companies: Wishlabs (AI Creativity), Wellture (Wellness), Learna (Education), Sparked (Media), Cosmic Jam (Entertainment), and Catalyst Apps (Utilities & Productivity). Each has full ownership and the depth to go further than anyone else in its space.

Codeway HQ powers them all. One platform. One team that finds and grows builders. One set of guardrails. Every idea born here starts with an unfair advantage: the platform, the people, and the profits of every product before it. That's the system.

Turns out you can do both.

Move like an indie. Hit like a giant.

POSITION

We're looking for an IAM Engineer to help run and improve the identity and access systems that every Codeway employee relies on. Okta is the front door to our environment, and you'll be hands-on with it every day: making sure people have the right access at the right time, keeping applications properly integrated, and building reliable processes that work quietly in the background.

You'll work across Okta, Google Workspace, Jamf, and the SaaS platforms our teams depend on. You'll onboard applications into SSO, maintain groups and entitlements, troubleshoot authentication and provisioning issues, and help keep our identity setup well-governed and reliable. A big part of the role will be looking at what's still being done manually and turning it into something automated, consistent, and dependable.

This is a hands-on role that combines identity engineering with day-to-day IT operations. You'll work the ticket queue, troubleshoot devices and applications, manage SaaS platforms, and be a visible technical presence in the Barcelona office. Roughly half of your time will focus on identity, access, and automation, with the other half covering IT support, endpoint management, and SaaS administration.

This is a hybrid role, based in our Barcelona office four days a week.

We welcome people with different backgrounds, experiences, and career paths. If you're excited about identity infrastructure, automation, and modern IT operations, we'd encourage you to apply even if you don't meet every qualification listed below. We care about what you can do, how you think, and your ability to learn as much as we care about what's already on your CV.

WHAT YOU'LL BE DOING?
Identity & Access Management
  • Administer our Okta environment day to day, including user assignments, authentication policies, MFA, sign-on rules, and application access.

  • Integrate new applications with SSO, working with application owners on SAML and OIDC configuration, attribute mapping, and testing.

  • Build and maintain SCIM provisioning integrations so account lifecycles stay automated and consistent across our SaaS environment.

  • Maintain our group, role, and entitlement model across Okta and Google Workspace, keeping access accurate and manageable as we scale.

  • Support access reviews and least-privilege initiatives, including identifying and removing unused accounts, stale groups, and unnecessary permissions.

  • Troubleshoot identity and access issues, including authentication, provisioning, MFA, and application access problems.

IT Support & Employee Lifecycle
  • Provide hands-on support to colleagues across identity, devices, connectivity, and SaaS, both in person in Barcelona and remotely for other locations.

  • Work the IT support queue, resolving requests within agreed service levels and escalating issues that require deeper investigation.

  • Set up, deploy, and troubleshoot laptops, peripherals, meeting room equipment, and other workplace technology.

  • Run joiner, mover, and leaver processes, ensuring access is granted, changed, and revoked reliably and on time, while delivering a strong first-day experience for new joiners.

  • Keep runbooks and internal documentation current, and identify recurring requests that can be turned into self-service, automation, or more repeatable processes.

Endpoint & SaaS Administration
  • Support our macOS fleet through Jamf Pro, including enrollment, configuration profiles, policies, and application deployment.

  • Administer business-critical SaaS platforms, including configuration, licensing, roles, permissions, and identity integrations.

  • Help bring unmanaged applications and tools under central identity and access governance.

  • Maintain accurate asset and inventory data across devices, accounts, applications, and licenses.

Automation & Improvement
  • Build automation for IT and identity workflows using scripting, APIs, and workflow tools.

  • Develop integrations between identity, endpoint, ITSM, and SaaS platforms to reduce manual handoffs and improve reliability.

  • Identify friction and recurring manual work in existing processes, and propose practical improvements.

  • Contribute to identity, endpoint, and IT operations standards as our environment evolves.

  • Document and share what you build, so that improvements become part of how the team operates.

WHAT YOU'LL BRING?
  • Hands-on experience administering an identity provider in production, ideally Okta, including application assignments, authentication policies, MFA, and user lifecycle management.

  • A solid understanding of identity fundamentals, including SSO, SAML, OIDC, SCIM, MFA, group and entitlement management, and least privilege.

  • Experience providing IT support in a cloud-first environment, with the patience and communication skills to support colleagues with different levels of technical experience.

  • Experience administering Google Workspace or a comparable productivity and collaboration platform.

  • Some experience automating repetitive work through scripting and APIs, using Python, Bash, or similar, and an interest in taking that further.

  • The ability to troubleshoot methodically, understand how systems connect, and work out what is actually happening rather than simply following a checklist.

  • Professional fluency in English, which is the working language across our offices.

NICE TO HAVE
  • Experience with Okta Workflows or comparable identity automation tooling.

  • Experience with macOS management through Jamf Pro, including Jamf Connect or similar identity-integrated login solutions.

  • Familiarity with identity and access management in AWS or GCP, including roles, policies, service accounts, and integration with an external identity provider.

  • Familiarity with ITSM platforms such as Freshservice.

  • Relevant certifications in identity, endpoint, or cloud disciplines. An Okta Certified Professional or Administrator certification is especially welcome.

OUR ENVIRONMENT

You'll help operate and improve a modern, cloud-first environment built around:

  • Okta

  • Google Workspace

  • Jamf Pro

  • Freshservice

  • AWS and Google Cloud Platform (GCP)

Beyond that, you'll work across a broad range of SaaS platforms including Slack, Zoom, Notion, GitHub, and others that we're progressively bringing under central identity and access governance.

We expect solid, hands-on Okta experience. You don't need to know everything else on day one. What matters is strong fundamentals, curiosity, and the ability to get productive quickly when working with an unfamiliar platform.

WHAT SUCCESS LOOKS LIKE

Within your first 12 months, you'll have:

  • Joiner, mover, and leaver processes running reliably, with fewer manual steps and clearer ownership.

  • New applications being integrated with SSO and automated provisioning as a routine part of the onboarding process.

  • A clean, understandable group and entitlement structure across our core platforms.

  • Access reviews supported end-to-end, with findings tracked through to remediation.

  • Consistent endpoint configuration across the fleet, with documentation that allows others to understand and maintain it.

  • A support experience colleagues trust, with issues picked up quickly and resolved effectively.

  • Several repetitive manual processes replaced with automation you've built and maintained.

  • Runbooks and documentation that make the environment easier to operate and less dependent on any one person.

The goal isn't simply to keep the existing setup running. It's to make it more reliable, more automated, and easier to operate as Codeway grows. You'll join a collaborative team where IT is viewed as an enabler, not a gatekeeper, and where you'll have the opportunity to grow into deeper identity and automation work as the company scales.

WHAT WE OFFER
  • A Competitive Compensation Package.
  • A Meal Compensation. That is actually enough for a decent & nutritious lunch, we’re not following the industry standard.
  • Full Health Benefits. To keep you away from all the trouble, we provide unlimited private health insurance and cover the HPV vaccine.
  • Pet Adoption Support. We cover the primary healthcare expenses, parasite vaccinations, and microchip costs that may arise within the first year after employees adopt a pet.
  • Cool Tech Stack. Macbook, iPhone 15 Pro, magic mouse, magic keyboard; an adjustable desk with a 4K screen and any other gadget you may need in your job.
  • Sport Activities Support. We care about your physical wellbeing and support your gym membership.
  • Flexible Schedule. This isn’t a “clock in, clock out” company. We care about your productivity, not tracking every minute you’re on site. It’s up to you to always be responsible with your work, no matter where you are or what schedule you’re keeping.
  • English Course Support. Be more global and perform best at your work.
  • A Top-Notch Office. Located at the heart of Barcelona in the iconic Edifici Estel.
  • Codebrew. Yes, you’ve heard it right: We love coffee so much that we’ve built our own coffee shop inside our office, where we also provide healthy snacks at all hours.
  • Free Breakfast & Lunch. At Codebrew - every day.
  • No Dress Code. Dress as you like.
  • Dream Team. Average Codeway member is young, talented, and passionate - which makes our working environment extremely dynamic. Need proof? Take a look at our Instagram.
  • Gaming Area. Whenever you need to take a break from hard work and relax with your favorite games, our PS5 corner will be waiting for you.
  • Software Support. Subscription to any software you might need to perform at your best.
  • Public Transportation Support. Daily public transportation support is on us, covered by an additional monthly compensation.
Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Senior Product Engineer - Factorial IT
Senior Product Engineer - Factorial IT

Talanto • Barcelona

Híbrido
EUR 90.000 - 130.000
High growth environment
Alan as private health insurance
Wellhub fitness program
+5
Full-Stack Developer
Full-Stack Developer

Kodify • Barcelona

Presencial
EUR 45.000 - 65.000
Generous vacation and personal days
1 month paid sabbatical after 3 years
Health & Wellness budget
+5
Corporate FP&A – Financial Planning
Corporate FP&A – Financial Planning

Codeway • Barcelona

Presencial
EUR 85.000 - 120.000
Relocation support
Private health insurance
Meal & travel card
+5
Senior Product Engineer - Operations Domain
Senior Product Engineer - Operations Domain

Talanto • Barcelona

Híbrido
EUR 70.000 - 100.000
Alan private health insurance
Wellhub gym access
Cobee
Corporate Fp&A Analyst Financial Planning
Corporate Fp&A Analyst Financial Planning

Codeway • Laza

Presencial
EUR 3800 - 5800
Health insurance
Meal card
Relocation support
Senior Software Engineer - Data
Senior Software Engineer - Data

Talanto • Barcelona

Presencial
EUR 70.000 - 110.000
Health insurance
Flexible working hours
Professional development budget
+1
Technical Solutions Engineer (FDE)
Technical Solutions Engineer (FDE)

Factorial HR • Barcelona

Híbrido
EUR 90.000 - 120.000
Private health insurance
Wellhub gym access
Cobee benefits management
+2
IT Systems & IAM Engineer
IT Systems & IAM Engineer

Factorial HR • Madrid

Híbrido
EUR 36.000 - 42.000
Salary range €36,300–€41,800
Private health insurance
Wellhub access
+3
Java Spring Boot & Cloud Sr. Software Engineer (d/f/m)
Java Spring Boot & Cloud Sr. Software Engineer (d/f/m)

Haufe Group • Barcelona

Híbrido
EUR 70.000 - 100.000
IT Systems & IAM Engineer
IT Systems & IAM Engineer

Factorial HR • Barcelona

Híbrido
EUR 36.000 - 42.000
Alan private health insurance
Wellhub (Gyms, pools, outdoor classes)
Cobee
+5