Software Engineer (Partner Identity & Access Management, ABU)
Booking.com · Amsterdam, Netherlands
About The Role
Join <Booking.com> as a Software Engineer in the Partner Identity & Access Management (PIAM) team. In this hands-on engineering role, you will work across the partner authentication estate, taking ownership of problems and outcomes rather than a fixed component. You will design, build, run, and evolve backend services that broker authentication between <Booking.com>'s partner systems and the identity provider. You will also deliver migration workstreams, maintain and change the legacy estate, configure and extend the identity platform, lead technical investigations, measure changes on real traffic, support the wider team and its consumers, and participate in on-call for services with a direct partner-visible blast radius.
- Conception, construction, operation, and evolution of backend services that facilitate authentication between partner systems and the identity provider.
- Design and execution of phased cutovers of partner authentication from the legacy Perl stack to Auth0, including coexistence strategies and staged rollouts.
- Acting as a primary investigator for login-path incidents and anomalies, driving them to root cause, documenting findings, and implementing changes.
- Strong grasp of the underlying protocols and standards — OAuth 2.0, OpenID Connect, JWT, session management — at the level of debugging, not just configuring
- Experience running services in a cloud environment, with production ownership: deployment, observability, alerting, and incident response
- Clear written and spoken English, and the communication habits that come with supporting many stakeholders: precise incident write-ups, readable design documents, and patient explanation of identity concepts to non-specialists
- Demonstrated ability to work productively in large legacy codebases, including reading and safely changing code in languages you did not choose. Working knowledge of Perl is required, given that our legacy authentication estate is written in it
- Experience migrating authentication from an incumbent system to a new identity provider on live traffic, including coexistence between old and new stacks, staged rollout, user and credential migration, and rollback
- A track record of independent, evidence-led investigation of production problems that span multiple systems and organizational boundaries
- Professional backend engineering experience building and operating production services at scale in Java and Perl
- Practical, in-depth experience with Auth0 in production: tenant and application configuration, extending the authentication pipeline with custom logic, connection and user-store strategy, token and session design, and the operational realities of running on it
- Hands-on delivery of customer identity and access management (CIAM) for an external, non-employee user population — partners, merchants, customers, or similar. You have built authentication systems, not only consumed them
- Experience with controlled experimentation (A/B testing) on authentication or funnel-critical paths, including interpreting results where traffic quality is not uniform
- Familiarity with bot, automation, and abuse traffic patterns on login endpoints, and how they distort conventional success metrics
- Experience with mobile authentication (native app OIDC flows, token lifecycle, biometric or device-bound credentials)
- Exposure to AI-assisted engineering workflows — coding agents, automated review, or agentic tooling in the software development lifecycle — and an interest in helping the team adopt them well
- Experience with machine-to-machine and API authentication for third-party integrators
Similar roles you might like
See all →This is an external listing. JobSpring does not represent or verify the employer. Report this listing
