Full-Time

Senior IT Security Engineer

Codeway

Codeway

501-1,000 employees

Mobile apps and games, data-driven iterations

No salary listed

Barcelona, Spain

Hybrid

Hybrid role based in Barcelona.

Category
IT & Security (1)
Required Skills
Microsoft Azure
Incident Response
Vulnerability Analysis
AWS
Risk Management
REST APIs
Google Workspace
Google Cloud Platform

Get referred to Codeway

See people who can refer or advise you

Requirements
  • Experience building, operating, or improving security controls in cloud-first environments, including identity, SaaS, endpoint, or public cloud platforms.
  • Experience collaborating with IT, Engineering, and business stakeholders.
  • Experience investigating security incidents and supporting remediation efforts.
  • Strong understanding of identity, endpoint, and cloud security fundamentals.
  • Experience automating workflows through scripting, APIs, or workflow platforms.
  • Ability to balance security requirements with operational efficiency and a positive employee experience.
Responsibilities
  • Partner with teams to strengthen security monitoring, detection, and response capabilities.
  • Investigate security events, coordinate incident response activities, and continuously improve operational playbooks and response processes.
  • Develop security metrics and reporting that provide visibility, support prioritization and risk management, and demonstrate the effectiveness of security controls.
  • Strengthen security controls across identity, endpoint, and business-critical SaaS platforms.
  • Improve identity and access controls, including governance, privileged access management, multifactor authentication, conditional access, and device trust.
  • Establish endpoint security standards, monitoring capabilities, and remediation processes.
  • Partner with stakeholders to evaluate security considerations for new applications, vendors, and integrations.
  • Maintain and enhance security controls across cloud environments while promoting secure-by-default approaches.
  • Build and operate a sustainable vulnerability management process across infrastructure, cloud, endpoint, and SaaS environments, including prioritization, remediation tracking, and reporting.
  • Review cloud configurations, permissions, and security risks, partnering with teams on practical remediation strategies and secure-by-design approaches.
  • Design and implement automation that improves security operations and reduces manual effort.
  • Build integrations and workflows across security, identity, endpoint, and cloud platforms.
  • Contribute to architecture reviews, security standards, and long-term security roadmaps.
  • Support security governance, compliance, and audit readiness initiatives by helping implement, document, and maintain effective security controls and processes.
  • Partner with teams across the organization to promote secure working practices and help foster a positive security culture.
Desired Qualifications
  • Hands-on experience with identity, cloud, endpoint, or SaaS security platforms.
  • Experience building or maturing security programs, processes, or operational capabilities.
  • Experience with security tooling such as security information and event management, cloud security posture management, extended detection and response, vulnerability management, or endpoint management platforms.
  • Experience supporting compliance initiatives, modern identity architectures, artificial intelligence platforms, or emerging technologies.
  • Relevant certifications in cloud, endpoint, or security disciplines.
  • Experience with Google Workspace, Okta, Jamf, Amazon Web Services, or Google Cloud Platform.

Codeway creates mobile apps and games for a global audience. Its products are built using a data-driven process that emphasizes rapid iteration, user testing, and A/B testing to refine features and experiences. Revenue comes from in-app purchases, ads, and premium app sales as it serves a wide range of users from casual gamers to productivity app fans. The company leverages a large network of resources—performance marketing, branding, communication, and business intelligence—to support growth and long-term innovation. What sets Codeway apart is its explicit focus on data-backed development, a broad global reach, and its integrated use of marketing and analytics to improve products. The company aims to keep growing by dreaming, measuring, building, and repeating, attracting top talent to join its journey.

Company Size

501-1,000

Company Stage

Seed

Total Funding

$16M

Headquarters

Istanbul, Türkiye

Founded

2020

Get referred to Codeway

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Codeway launched NoteBook, Learna, and Retake, deepening its AI app lineup.
  • Its flagship apps remain heavily downloaded across Google Play and the App Store.
  • The company fixed the January 2026 Firebase issue within hours, showing response speed.

What critics are saying

  • January 20, 2026, Firehound exposed 300 million Chat & Ask AI messages.
  • Sensitive chats from 25 million users sat in publicly writable Firebase storage.
  • A major App Store privacy crackdown can destroy trust and distribution overnight.

What makes Codeway unique

  • Codeway ships 60+ AI apps, spanning education, creativity, and utilities.
  • Its portfolio has 150 million downloads and ranks among top 50 publishers.
  • Codeway builds fast, data-driven consumer products across iOS and Android globally.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Unlimited Paid Time Off

Flexible Work Hours

Wellness Program

Mental Health Support

Gym Membership

Professional Development Budget

Commuter Benefits

Growth & Insights and Company News

Headcount

6 month growth

-2%

1 year growth

0%

2 year growth

3%
Macworld
Jan 20th, 2026
These iPhone AI apps expose your data, and they're all over the App Store

These iphone AI apps expose your data, and they're all over the App Store. The Firehound Project is a public registry that hunts down AI apps that expose user data - and there are a ton of them. In summary: * Macworld reports that nearly 200 AI apps on the App Store expose sensitive user data through security vulnerabilities identified by CovertLabs' Firehound project. * The Chat & Ask AI app by Codeway exposed over 406,000 files containing user chats and personal information, highlighting significant privacy risks. * Users should verify app security using Firehound before downloading and exercise caution when sharing personal data with AI applications. AI apps are everywhere, and they sure seem like they can be incredibly useful, don't they? However, users need to be mindful of AI slop, inaccuracies, and hallucinations - and it turns out a lot of AI apps are a security risk, as well. A new project by AI security firm CovertLabs takes a look at AI apps in the App Store and indexes the apps that expose user data. The index, called Firehound, is available to view online and provides a tally of the files exposed by the app. Nearly 200 apps are listed in Firehound, with a large number of them still available in the App Store. There are tons of image generators, chatbots, and photo animators, the exact kind of apps people would be searching for. The app with the most files exposed on Firehound's registry is Chat & Ask AI by Codeway, a chatbot that has Deep Flow Software Services-FZCO listed as the seller. The app has exposed over 406 thousand files that include user chats and user information. A January 20th X post by Harrris0n (whose bio includes a direct link to CovertLabs) states that the app's "problem has been addressed, and the vulnerability no longer exists." But according to the App Store, Chat & Ask AI is at version 3.3.8, which was released on January 7. Firehound's registry for the app is dated January 15, 2026, so it does not appear that the fixed version has been made available to the public. The purpose of Firehound is to let developers know that breaches have been found in their apps so they can be fixed. When visiting Firehound, a "Responsible Disclosure" pop-up appears (see above) to provide developers a way to contact CovertLabs, learn how to fix the app, and have the app removed from the registry. Registration is required to access CovertLabs' research and results. Users can make good use of Firehound, as well. It can be used as a source to check the security of an AI app they may be considering in the App Store. How did these apps get onto the App Store with their security holes in the first place? That is unknown. Firehound is a good reminder to users that all AI apps rely on personal information, and that users need to be aware of the data being provided and how much of it they are willing to expose. With AI being the new frontier, companies are quick to develop tools to stake a claim, but those tools may lack the proper security implementations. Roman is a Macworld Senior Editor with over 30 years of experience covering the tech industry, focusing on the Mac and other products in the Apple ecosystem. He is also the host of the Macworld Podcast. His career started at MacUser, where he received Apple certification as a repair technician (when Apple did that kind of thing). He's also worked for MacAddict, MacLife, and TechTV.