Skip to sign up

Job matched to your search

Software Engineer II - Partner Identity & Access Management - ABU

Booking.com · Amsterdam

Amsterdam · HybridFull-TimePosted Sep 4, 2026

Free · Join 5,000+ job seekers using Qarera

How well do you match this role?

Tap the skills you already have — then see your real match score, what’s missing, and your resume fixed for this job.

↑ tap the skills you have
Loading sign-in…
Free · no credit card · 30 seconds

Job description

Please note: relocation support is not provided for this role. About Us: At Booking.com, data drives our decisions. Technology is at our core. And innovation is everywhere. But our company is more than datasets, lines of code or A/B tests. We’re the thrill of the first night in a new place. The excitement of the next morning. The friends you encounter. The journeys you take. The sights you see. And the memories you make. Through our products, partners and people, we make it easier for everyone to experience the world.

About the team:

Partner Identity & Access Management (PIAM) owns how Booking.com's accommodation partners prove who they are and what they're allowed to do. Every partner-facing surface depends on us. Together these carry roughly millions of logins a day.

We are in the middle of a multi-year replatforming of that estate. Partner authentication is moving off a long-lived, in-house Perl system onto Auth0, without downtime, without partners noticing, and without regressing login success — while the legacy system continues to serve live traffic alongside the new one. The work is unusually high-stakes for its size: a bad release doesn't degrade an experience, it locks partners out of their business.

The role

You will work across the partner authentication estate: the services that broker authentication flows, the long-lived systems that still carry production traffic, the identity platform they run against, and the integrations that hundreds of downstream consumers depend on. Ownership here is of problems and outcomes rather than a fixed component — what you hold changes as the migration moves, and engineers on this team are expected to follow the work rather than defend a boundary.

This is a hands-on engineering role in a live, complex, production-critical system, not a greenfield build. Much of the value is in understanding systems you did not write deeply enough to change them safely, and in being the person others can rely on when the login path misbehaves.

Key responsibilities and duties

  • Build and operate backend services across partner authentication. Design, build, run, and evolve services that broker authentication between Booking.com's partner systems and the identity provider — their data models, APIs, caching and consistency behaviour, and failure modes — taking full ownership of what you ship.
  • Deliver migration workstreams. Design and execute phased cutovers of partner authentication from the legacy Perl stack to Auth0 — coexistence strategies, dual-write and reconciliation paths, staged rollouts, and rollback plans that hold under live traffic.
  • Maintain and change the legacy estate. Read, debug, and safely modify long-lived Perl services that still carry production authentication traffic, and progressively reduce our dependency on them.
  • Configure and extend the identity platform. Implement authentication and authorization behaviour in Auth0 — tenant and application configuration, custom logic in the authentication pipeline, connection and directory strategy, token and session design — and encode that configuration as reviewable, versioned artifacts rather than console changes.
  • Lead technical investigations. Act as a primary investigator for login-path incidents and anomalies spanning our services, the identity provider, edge infrastructure, and partner integrations. Drive these to root cause, write them up, and turn findings into changes.
  • Measure changes on real traffic. Instrument authentication flows, define and defend the metrics that describe login health, and run controlled experiments to validate that migration steps are neutral or positive for partners.
  • Support the wider team and its consumers. Act as a go-to technical reference on partner identity for engineers inside and outside PIAM: unblock integrations, review designs that touch authentication, and raise the team's collective understanding of the domain.
  • Participate in on-call for services with a direct partner-visible blast radius.

Role Qualifications & Skills

  • Professional backend engineering experience building and operating production services at scale in Java and Perl.
  • Hands-on delivery of customer identity and access management (CIAM) for an external, non-employee user population — partners, merchants, customers, or similar. You have built authentication systems, not only consumed them.
  • Practical, in-depth experience with Auth0 in production: tenant and application configuration, extending the authentication pipeline with custom logic, connection and user-store strategy, token and session design, and the operational realities of running on it.
  • Experience migrating authentication from an incumbent system to a new identity provider on live traffic, including coexistence between old and new stacks, staged rollout, user and credential migration, and rollback.
  • Demonstrated ability to work productively in large legacy codebases, including reading and safely changing code in languages you did not choose. Working knowledge of Perl is required, given that our legacy authentication estate is written in it.
  • Strong grasp of the underlying protocols and standards — OAuth 2.0, OpenID Connect, JWT, session management — at the level of debugging, not just configuring.
  • Experience running services in a cloud environment, with production ownership: deployment, observability, alerting, and incident response.
  • A track record of independent, evidence-led investigation of production problems that span multiple systems and organizational boundaries.
  • Clear written and spoken English, and the communication habits that come with supporting many stakeholders: precise incident write-ups, readable design documents, and patient explanation of identity concepts to non-specialists.

Preferred

  • Experience with controlled experimentation (A/B testing) on authentication or funnel-critical paths, including interpreting results where traffic quality is not uniform.
  • Familiarity with bot, automation, and abuse traffic patterns on login endpoints, and how they distort conventional success metrics.
  • Experience with mobile authentication (native app OIDC flows, token lifecycle, biometric or device-bound credentials).
  • Exposure to AI-assisted engineering workflows — coding agents, automated review, or agentic tooling in the software development lifecycle — and an interest in helping the team adopt them well.
  • Experience with machine-to-machine and API authentication for third-party integrators.

Benefits & Perks - Global Impact, Personal Relevance: Booking.com’s Total Rewards Philosophy is not only about compensation but also about benefits. We offer a competitive compensation and benefits package, as well unique-to-Booking.com benefits which include:

  • Annual paid time off and generous paid leave scheme including: parent, grandparent, bereavement, and care leave
  • Hybrid working including flexible working arrangements, and up to 20 days per year working from abroad (home country)
  • Industry leading product discounts - up to 1400 per year - for yourself, including automatic Genius Level 3 status and Booking.com wallet credit

Inclusion at Booking.com: Inclusion has been a core part of our company culture since day one. This ongoing journey starts with our very own employees, who represent over 140 nationalities and a wide range of ethnic and social backgrounds, genders and sexual orientations.

Take it from our Chief People Officer, Paulo Pisano: “At Booking.com, the diversity of our people doesn’t just build an outstanding workplace, it also creates a better and more inclusive travel experience for everyone. Inclusion is at the heart of everything we do. It’s a place where you can make your mark and have a real impact in travel and tech.”

We ensure that colleagues with disabilities are provided the adjustments and tools they need to participate in the job application and interview process, to perform crucial job functions, and to receive other benefits and privileges of employment.

Pre-Employment Screening If your application is successful, your personal data may be used for a pre-employment screening check by a third party as permitted by applicable law. Depending on the vacancy and applicable law, a pre-employment screening may include employment history, education and other information (such as media information) that may be necessary for determining your qualifications and suitability for the position.

Don’t just read the job — see if you’ll get it.

Get your match score, a resume tailored to this exact role, and jobs like it — free.

Check my fit for this job
Loading sign-in…
Apply →

Hiring for a role like this? Join the employer waitlist.