Software Engineer (Partner Identity & Access Management, ABU)
Booking.com
senior
Location
Amsterdam, Netherlands
Work Type
Onsite
Seniority
senior
Posted
September 11, 2026
Total Compensation
€175,000
Yearly Savings (Comfortable)
€87,000
Want to apply for this job?
Subscribe to access the application link and 15,000+ more jobs
Job Description
- You will work across the partner authentication estate: the services that broker authentication flows, the long-lived systems that still carry production traffic, the identity platform they run against, and the integrations that hundreds of downstream consumers depend on
- Ownership here is of problems and outcomes rather than a fixed component — what you hold changes as the migration moves, and engineers on this team are expected to follow the work rather than defend a boundary
- This is a hands-on engineering role in a live, complex, production-critical system, not a greenfield build. Much of the value is in understanding systems you did not write deeply enough to change them safely, and in being the person others can rely on when the login path misbehaves
- Build and operate backend services across partner authentication. Design, build, run, and evolve services that broker authentication between Booking.com’s partner systems and the identity provider — their data models, APIs, caching and consistency behaviour, and failure modes — taking full ownership of what you ship
- Deliver migration workstreams. Design and execute phased cutovers of partner authentication from the legacy Perl stack to Auth0 — coexistence strategies, dual-write and reconciliation paths, staged rollouts, and rollback plans that hold under live traffic
- Maintain and change the legacy estate. Read, debug, and safely modify long-lived Perl services that still carry production authentication traffic, and progressively reduce our dependency on them
- Configure and extend the identity platform. Implement authentication and authorization behaviour in Auth0 — tenant and application configuration, custom logic in the authentication pipeline, connection and directory strategy, token and session design — and encode that configuration as reviewable, versioned artifacts rather than console changes
- Lead technical investigations. Act as a primary investigator for login-path incidents and anomalies spanning our services, the identity provider, edge infrastructure, and partner integrations. Drive these to root cause, write them up, and turn findings into changes
- Measure changes on real traffic. Instrument authentication flows, define and defend the metrics that describe login health, and run controlled experiments to validate that migration steps are neutral or positive for partners
- Support the wider team and its consumers. Act as a go-to technical reference on partner identity for engineers inside and outside PIAM: unblock integrations, review designs that touch authentication, and raise the team’s collective understanding of the domain
- Participate in on-call for services with a direct partner-visible blast radius
Benefits
- Health insurance
- Free access to Headspace for you and your loved ones
- Global Employee Assistance Program
- Meditation and Breastfeeding rooms at the office
- Booking Cares - 2 days per year to volunteer and learn
- Life insurance
- Disability insurance
- Pension plan
- Annual paid time off
- Parental leave - 22 weeks
- Grandparent leave - 10 days
- Care leave - 10 days
- Bereavement leave - up to 4 weeks
- Anniversary leave
- Working from Home Furniture and Ergonomic Support
- Working from Abroad - up to 20 days per year
- Discounts & Wallet credits to spend on our products
- Upgrade to Booking.com Genius Level 3
- Friends & Family Booking.com discount vouchers
- Free access to online learning platforms
- Development and mentorship programs to support career growth
- Access to trainings and workshops
- Team development opportunities
- Local discount programs
- Game rooms in offices
- On-site meals, coffee and snacks including vegan options- Strong grasp of the underlying protocols and standards — OAuth 2.0, OpenID Connect, JWT, session management — at the level of debugging, not just configuring
- Experience running services in a cloud environment, with production ownership: deployment, observability, alerting, and incident response
- Clear written and spoken English, and the communication habits that come with supporting many stakeholders: precise incident write-ups, readable design documents, and patient explanation of identity concepts to non-specialists
- Demonstrated ability to work productively in large legacy codebases, including reading and safely changing code in languages you did not choose. Working knowledge of Perl is required, given that our legacy authentication estate is written in it
- Experience migrating authentication from an incumbent system to a new identity provider on live traffic, including coexistence between old and new stacks, staged rollout, user and credential migration, and rollback
- A track record of independent, evidence-led investigation of production problems that span multiple systems and organizational boundaries
- Professional backend engineering experience building and operating production services at scale in Java and Perl
- Practical, in-depth experience with Auth0 in production: tenant and application configuration, extending the authentication pipeline with custom logic, connection and user-store strategy, token and session design, and the operational realities of running on it
- Hands-on delivery of customer identity and access management (CIAM) for an external, non-employee user population — partners, merchants, customers, or similar. You have built authentication systems, not only consumed them
- Experience with controlled experimentation (A/B testing) on authentication or funnel-critical paths, including interpreting results where traffic quality is not uniform
- Familiarity with bot, automation, and abuse traffic patterns on login endpoints, and how they distort conventional success metrics
- Experience with mobile authentication (native app OIDC flows, token lifecycle, biometric or device-bound credentials)
- Exposure to AI-assisted engineering workflows — coding agents, automated review, or agentic tooling in the software development lifecycle — and an interest in helping the team adopt them well
- Experience with machine-to-machine and API authentication for third-party integrators
More Jobs You Might Like
Helpful Resources
Salary & Savings Calculator
Compare salaries across European cities and calculate your potential savings. Understand cost of living and take-home pay for tech jobs in Europe.
Career Guides
Expert advice on landing high-paying tech jobs in Europe. Tips on interviews, salary negotiation, and career growth from The European Engineer.
Access 15,000+ High-Paying Tech Jobs
Get unlimited access to our full database of 15,000+ jobs with advanced filters, salary comparisons, and exclusive career guides from The European Engineer.