> Markdown version of [/jobs/ext/3005107-software-engineer-iam-identity-and-access-management](https://www.wearedevelopers.com/jobs/ext/3005107-software-engineer-iam-identity-and-access-management). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Software Engineer - Iam (Identity And Access Management - **Company:** Codeway Hq - **Location:** Barcelona, Spain - **Salary:** €40,000.0 - €75,000.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Amazon Web Services, User Authentication, Build Automation, Bash Shell, Software as a Service, Collaborative Software, Github, Identity and Access Management, Information Technology Operations, Inventory Management Software, Python (Programming Language), Microsoft OneNote, OpenID, Role-Based Access Control, Runbook, Security Assertion Markup Language (SAML), Single Sign-On, Software Deployment, Systems Integration, Workflow Management Systems, Scripting, Google Cloud, Okta, Casper Suite, Gsuite - **Published:** September 19, 2026 - **Apply:** https://www.adzuna.es/contact-us.html ## About the Role + Hands-on experience administering an identity provider in production, ideally Okta, including application assignments, authentication policies, MFA, and user lifecycle management. + A solid understanding of identity fundamentals, including SSO, SAML, OIDC, SCIM, MFA, group and entitlement management, and least privilege. + Experience providing IT support in a cloud-first environment, with the patience and communication skills to support colleagues with different levels of technical experience. + Experience administering Google Workspace or a comparable productivity and collaboration platform. + Some experience automating repetitive work through scripting and APIs, using Python, Bash, or similar, and an interest in taking that further. + The ability to troubleshoot methodically, understand how systems connect, and work out what is actually happening rather than simply following a checklist. + Professional fluency in English, which is the working language across our offices. NICE TO HAVE + Experience with Okta Workflows or comparable identity automation tooling. + Experience with macOS management through Jamf Pro, including Jamf Connect or similar identity-integrated login solutions. + Familiarity with identity and access management in AWS or GCP, including roles, policies, service accounts, and integration with an external identity provider. + Familiarity with ITSM platforms such as Freshservice. + Relevant certifications in identity, endpoint, or cloud disciplines. An Okta Certified Professional or Administrator certification is especially welcome. ## Description We're looking for an IAM Engineer to help run and improve the identity and access systems that every Codeway employee relies on. Okta is the front door to our environment, and you'll be hands-on with it every day: making sure people have the right access at the right time, keeping applications properly integrated, and building reliable processes that work quietly in the background. You'll work across Okta, Google Workspace, Jamf, and the SaaS platforms our teams depend on. You'll onboard applications into SSO, maintain groups and entitlements, troubleshoot authentication and provisioning issues, and help keep our identity setup well-governed and reliable. A big part of the role will be looking at what's still being done manually and turning it into something automated, consistent, and dependable. This is a hands-on role that combines identity engineering with day-to-day IT operations. You'll work the ticket queue, troubleshoot devices and applications, manage SaaS platforms, and be a visible technical presence in the Barcelona office. Roughly half of your time will focus on identity, access, and automation, with the other half covering IT support, endpoint management, and SaaS administration. This is a hybrid role, based in our Barcelona office four days a week. We welcome people with different backgrounds, experiences, and career paths. If you're excited about identity infrastructure, automation, and modern IT operations, we'd encourage you to apply even if you don't meet every qualification listed below. We care about what you can do, how you think, and your ability to learn as much as we care about what's already on your CV. WHAT YOU'LL BE DOING?Identity & Access Management + Administer our Okta environment day to day, including user assignments, authentication policies, MFA, sign-on rules, and application access. + Integrate new applications with SSO, working with application owners on SAML and OIDC configuration, attribute mapping, and testing. + Build and maintain SCIM provisioning integrations so account lifecycles stay automated and consistent across our SaaS environment. + Maintain our group, role, and entitlement model across Okta and Google Workspace, keeping access accurate and manageable as we scale. + Support access reviews and least-privilege initiatives, including identifying and removing unused accounts, stale groups, and unnecessary permissions. + Troubleshoot identity and access issues, including authentication, provisioning, MFA, and application access problems. IT Support & Employee Lifecycle + Provide hands-on support to colleagues across identity, devices, connectivity, and SaaS, both in person in Barcelona and remotely for other locations. + Work the IT support queue, resolving requests within agreed service levels and escalating issues that require deeper investigation. + Set up, deploy, and troubleshoot laptops, peripherals, meeting room equipment, and other workplace technology. + Run joiner, mover, and leaver processes, ensuring access is granted, changed, and revoked reliably and on time, while delivering a strong first-day experience for new joiners. + Keep runbooks and internal documentation current, and identify recurring requests that can be turned into self-service, automation, or more repeatable processes. Endpoint & SaaS Administration + Support our macOS fleet through Jamf Pro, including enrollment, configuration profiles, policies, and application deployment. + Administer business-critical SaaS platforms, including configuration, licensing, roles, permissions, and identity integrations. + Help bring unmanaged applications and tools under central identity and access governance. + Maintain accurate asset and inventory data across devices, accounts, applications, and licenses. Automation & Improvement + Build automation for IT and identity workflows using scripting, APIs, and workflow tools. + Develop integrations between identity, endpoint, ITSM, and SaaS platforms to reduce manual handoffs and improve reliability. + Identify friction and recurring manual work in existing processes, and propose practical improvements. + Contribute to identity, endpoint, and IT operations standards as our environment evolves. + Document and share what you build, so that improvements become part of how the team operates., You'll help operate and improve a modern, cloud-first environment built around: + Okta + Google Workspace + Jamf Pro + Freshservice + AWS and Google Cloud Platform (GCP) Beyond that, you'll work across a broad range of SaaS platforms including Slack, Zoom, Notion, GitHub, and others that we're progressively bringing under central identity and access governance. We expect solid, hands-on Okta experience. You don't need to know everything else on day one. What matters is strong fundamentals, curiosity, and the ability to get productive quickly when working with an unfamiliar platform. WHAT SUCCESS LOOKS LIKE Within your first 12 months, you'll have: + Joiner, mover, and leaver processes running reliably, with fewer manual steps and clearer ownership. + New applications being integrated with SSO and automated provisioning as a routine part of the onboarding process. + A clean, understandable group and entitlement structure across our core platforms. + Access reviews supported end-to-end, with findings tracked through to remediation. + Consistent endpoint configuration across the fleet, with documentation that allows others to understand and maintain it. + A support experience colleagues trust, with issues picked up quickly and resolved effectively. + Several repetitive manual processes replaced with automation you've built and maintained. + Runbooks and documentation that make the environment easier to operate and less dependent on any one person. The goal isn't simply to keep the existing setup running. It's to make it more reliable, more automated, and easier to operate as Codeway grows. You'll join a collaborative team where IT is viewed as an enabler, not a gatekeeper, and where you'll have the opportunity to grow into deeper identity and automation work as the company scales., Kyndryl Madrid HQ (KES51610) Identity & Access Management (IAM) Consultant Kyndryl Madrid Software Engineer - IAM (Identity and Access Management) 40000-75000 per year Prima Madrid Software Engineer - IAM (Identity and Access Management) (copy) Prima Madrid Software Engineer - Iam (Identity And Access Management) New Prima Madrid, Madrid ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Our GitOps approach for deploying an Identity Provider and an API Gateway in a SaaS company](https://www.wearedevelopers.com/videos/776-our-gitops-approach-for-deploying-an-identity-provider-and-an-api-gateway-in-a-saas-company) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [Backstage in Practice: Offloading Developer Operational Work Through Platform Self-Service](https://www.wearedevelopers.com/videos/1922-backstage-in-practice-offloading-developer-operational-work-through-platform-self-service) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Going Beyond Passwords: The Future of User Authentication](https://www.wearedevelopers.com/videos/714-going-beyond-passwords-the-future-of-user-authentication) ## Related Articles - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Find a Developer Job: 12 Best Job Sites For Developers](https://www.wearedevelopers.com/magazine/165-find-a-developer-job-12-best-job-sites-for-developers) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs)