Identity & Access Management (IAM) Engineer, IT
CodewayABOUT CODEWAY
Codeway builds category-leading consumer AI apps on mobile and web, at global scale.
600M+ downloads. 60+ apps. 400+ builders across Barcelona and İstanbul. Completely bootstrapped. No board. Profitable since year two.
Small teams move faster than big ones. But they need big resources to win at scale. Nobody starts from zero. The problem decides the solution, not us.
We turn category wins into six focused vertical companies: Wishlabs (AI Creativity), Wellture (Wellness), Learna (Education), Sparked (Media), Cosmic Jam (Entertainment), and Catalyst Apps (Utilities & Productivity). Each has full ownership and the depth to go further than anyone else in its space.
Codeway HQ powers them all. One platform. One team that finds and grows builders. One set of guardrails. Every idea born here starts with an unfair advantage: the platform, the people, and the profits of every product before it. That's the system.
Turns out you can do both.
Move like an indie. Hit like a giant.
POSITION
We're looking for an IAM Engineer to help run and improve the identity and access systems that every Codeway employee relies on. Okta is the front door to our environment, and you'll be hands-on with it every day: making sure people have the right access at the right time, keeping applications properly integrated, and building reliable processes that work quietly in the background.
You'll work across Okta, Google Workspace, Jamf, and the SaaS platforms our teams depend on. You'll onboard applications into SSO, maintain groups and entitlements, troubleshoot authentication and provisioning issues, and help keep our identity setup well-governed and reliable. A big part of the role will be looking at what's still being done manually and turning it into something automated, consistent, and dependable.
This is a hands-on role that combines identity engineering with day-to-day IT operations. You'll work the ticket queue, troubleshoot devices and applications, manage SaaS platforms, and be a visible technical presence in the Barcelona office. Roughly half of your time will focus on identity, access, and automation, with the other half covering IT support, endpoint management, and SaaS administration.
This is a hybrid role, based in our Barcelona office four days a week.
We welcome people with different backgrounds, experiences, and career paths. If you're excited about identity infrastructure, automation, and modern IT operations, we'd encourage you to apply even if you don't meet every qualification listed below. We care about what you can do, how you think, and your ability to learn as much as we care about what's already on your CV.
WHAT YOU'LL BE DOING?
Identity & Access Management
Administer our Okta environment day to day, including user assignments, authentication policies, MFA, sign-on rules, and application access.
Integrate new applications with SSO, working with application owners on SAML and OIDC configuration, attribute mapping, and testing.
Build and maintain SCIM provisioning integrations so account lifecycles stay automated and consistent across our SaaS environment.
Maintain our group, role, and entitlement model across Okta and Google Workspace, keeping access accurate and manageable as we scale.
Support access reviews and least-privilege initiatives, including identifying and removing unused accounts, stale groups, and unnecessary permissions.
Troubleshoot identity and access issues, including authentication, provisioning, MFA, and application access problems.
IT Support & Employee Lifecycle
Provide hands-on support to colleagues across identity, devices, connectivity, and SaaS, both in person in Barcelona and remotely for other locations.
Work the IT support queue, resolving requests within agreed service levels and escalating issues that require deeper investigation.
Set up, deploy, and troubleshoot laptops, peripherals, meeting room equipment, and other workplace technology.
Run joiner, mover, and leaver processes, ensuring access is granted, changed, and revoked reliably and on time, while delivering a strong first-day experience for new joiners.
Keep runbooks and internal documentation current, and identify recurring requests that can be turned into self-service, automation, or more repeatable processes.
Endpoint & SaaS Administration
Support our macOS fleet through Jamf Pro, including enrollment, configuration profiles, policies, and application deployment.
Administer business-critical SaaS platforms, including configuration, licensing, roles, permissions, and identity integrations.
Help bring unmanaged applications and tools under central identity and access governance.
Maintain accurate asset and inventory data across devices, accounts, applications, and licenses.
Automation & Improvement
Build automation for IT and identity workflows using scripting, APIs, and workflow tools.
Develop integrations between identity, endpoint, ITSM, and SaaS platforms to reduce manual handoffs and improve reliability.
Identify friction and recurring manual work in existing processes, and propose practical improvements.
Contribute to identity, endpoint, and IT operations standards as our environment evolves.
Document and share what you build, so that improvements become part of how the team operates.
WHAT YOU'LL BRING?
Hands-on experience administering an identity provider in production, ideally Okta, including application assignments, authentication policies, MFA, and user lifecycle management.
A solid understanding of identity fundamentals, including SSO, SAML, OIDC, SCIM, MFA, group and entitlement management, and least privilege.
Experience providing IT support in a cloud-first environment, with the patience and communication skills to support colleagues with different levels of technical experience.
Experience administering Google Workspace or a comparable productivity and collaboration platform.
Some experience automating repetitive work through scripting and APIs, using Python, Bash, or similar, and an interest in taking that further.
The ability to troubleshoot methodically, understand how systems connect, and work out what is actually happening rather than simply following a checklist.
Professional fluency in English, which is the working language across our offices.
NICE TO HAVE
Experience with Okta Workflows or comparable identity automation tooling.
Experience with macOS management through Jamf Pro, including Jamf Connect or similar identity-integrated login solutions.
Familiarity with identity and access management in AWS or GCP, including roles, policies, service accounts, and integration with an external identity provider.
Familiarity with ITSM platforms such as Freshservice.
Relevant certifications in identity, endpoint, or cloud disciplines. An Okta Certified Professional or Administrator certification is especially welcome.
OUR ENVIRONMENT
You'll help operate and improve a modern, cloud-first environment built around:
Okta
Google Workspace
Jamf Pro
Freshservice
AWS and Google Cloud Platform (GCP)
Beyond that, you'll work across a broad range of SaaS platforms including Slack, Zoom, Notion, GitHub, and others that we're progressively bringing under central identity and access governance.
We expect solid, hands-on Okta experience. You don't need to know everything else on day one. What matters is strong fundamentals, curiosity, and the ability to get productive quickly when working with an unfamiliar platform.
WHAT SUCCESS LOOKS LIKE
Within your first 12 months, you'll have:
Joiner, mover, and leaver processes running reliably, with fewer manual steps and clearer ownership.
New applications being integrated with SSO and automated provisioning as a routine part of the onboarding process.
A clean, understandable group and entitlement structure across our core platforms.
Access reviews supported end-to-end, with findings tracked through to remediation.
Consistent endpoint configuration across the fleet, with documentation that allows others to understand and maintain it.
A support experience colleagues trust, with issues picked up quickly and resolved effectively.
Several repetitive manual processes replaced with automation you've built and maintained.
Runbooks and documentation that make the environment easier to operate and less dependent on any one person.
The goal isn't simply to keep the existing setup running. It's to make it more reliable, more automated, and easier to operate as Codeway grows. You'll join a collaborative team where IT is viewed as an enabler, not a gatekeeper, and where you'll have the opportunity to grow into deeper identity and automation work as the company scales.
WHAT WE OFFER
· A Competitive Compensation Package. Long story short, we take care of you.
· A Meal Compensation. That is actually enough for a decent & nutritious lunch, we’re not following the industry standard.
· Full Health Benefits. To keep you away from all the trouble, we provide unlimited private health insurance and cover the HPV vaccine.
· Pet Adoption Support. We cover the primary healthcare expenses, parasite vaccinations, and microchip costs that may arise within the first year after employees adopt a pet.
· Cool Tech Stack. Macbook, iPhone 15 Pro, magic mouse, magic keyboard; an adjustable desk with a 4K screen and any other gadget you may need in your job.
· Sport Activities Support. We care about your physical wellbeing and support your gym membership.
· Flexible Schedule. This isn’t a “clock in, clock out” company. We care about your productivity, not tracking every minute you’re on site. It’s up to you to always be responsible with your work, no matter where you are or what schedule you’re keeping.
· English Course Support. Be more global and perform best at your work.
· A Top-Notch Office. Located at the heart of Barcelona in the iconic Edifici Estel.
· Codebrew. Yes, you’ve heard it right: We love coffee so much that we’ve built our own coffee shop inside our office, where we also provide healthy snacks at all hours.
· Free Breakfast & Lunch. At Codebrew - every day.
· No Dress Code. Dress as you like.
· Dream Team. Average Codeway member is young, talented, and passionate - which makes our working environment extremely dynamic. Need proof? Take a look at our Instagram.
· Gaming Area. Whenever you need to take a break from hard work and relax with your favorite games, our PS5 corner will be waiting for you.
· Software Support. Subscription to any software you might need to perform at your best.
· Public Transportation Support. Daily public transportation support is on us, covered by an additional monthly compensation.
THE RECRUITING PROCESS
We are committed to keeping our recruitment process short and transparent. Here’s how it looks like:
Application: Send us your CV or LinkedIn profile. You can also just write a few words about yourself.
Talent & Culture Interview: Let’s talk about your experience & expectations and see what we can achieve together.
Case Study: We might send you a task to solve.
Technical Interview: You will meet with your future team lead to go over the case and your technical capabilities in detail.
Final Interview: A final interview with one of our senior leaders.
Welcome Aboard! You are now a part of the team.
Your personal data that will be collected through your applications made due to this advertisement will be processed automatically by the data controller Codeway in accordance with the Personal Data Protection Law No. 6698 ("KVKK") and relevant legislation for the purpose of conducting job application processes. You can access detailed information on this matter from the "Candidate Information Notice"page at https://www.codeway.co. Codeway processes the personal data of job applicants in accordance with relevant legislation. "Privacy Notice for Employee Candidate" summarizes the data processing procedures during the application process.