> Markdown version of [/jobs/ext/3192422-software-engineer-ii-partner-identity-access-management-abu](https://www.wearedevelopers.com/jobs/ext/3192422-software-engineer-ii-partner-identity-access-management-abu). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Software Engineer II - Partner Identity & Access Management - ABU - **Company:** Booking.com - **Location:** Amsterdam, Netherlands - **Contract:** Permanent contract - **Skills:** Java (Programming Language), A/B Testing, Application Programming Interfaces (APIs), Artificial Intelligence, Application Configuration Access Protocols, Biometrics, Cloud Computing, Software Debugging, Software Design Documents, Perl (Programming Language), Identity and Access Management, OAuth, OpenID, Openid Connect, JSON Web Token, Session Management, Software Engineering, Caching, Backend, Customer Identity Access Management - **Published:** September 4, 2026 - **Apply:** https://nl.indeed.com/viewjob?jk=0d8b714fc6ddb9b6 ## About the Role * Professional backend engineering experience building and operating production services at scale in Java and Perl. * Hands-on delivery of customer identity and access management (CIAM) for an external, non-employee user population - partners, merchants, customers, or similar. You have built authentication systems, not only consumed them. * Practical, in-depth experience with Auth0 in production: tenant and application configuration, extending the authentication pipeline with custom logic, connection and user-store strategy, token and session design, and the operational realities of running on it. * Experience migrating authentication from an incumbent system to a new identity provider on live traffic, including coexistence between old and new stacks, staged rollout, user and credential migration, and rollback. * Demonstrated ability to work productively in large legacy codebases, including reading and safely changing code in languages you did not choose. Working knowledge of Perl is required, given that our legacy authentication estate is written in it. * Strong grasp of the underlying protocols and standards - OAuth 2.0, OpenID Connect, JWT, session management - at the level of debugging, not just configuring. * Experience running services in a cloud environment, with production ownership: deployment, observability, alerting, and incident response. * A track record of independent, evidence-led investigation of production problems that span multiple systems and organizational boundaries. * Clear written and spoken English, and the communication habits that come with supporting many stakeholders: precise incident write-ups, readable design documents, and patient explanation of identity concepts to non-specialists., * Experience with controlled experimentation (A/B testing) on authentication or funnel-critical paths, including interpreting results where traffic quality is not uniform. * Familiarity with bot, automation, and abuse traffic patterns on login endpoints, and how they distort conventional success metrics. * Experience with mobile authentication (native app OIDC flows, token lifecycle, biometric or device-bound credentials). * Exposure to AI-assisted engineering workflows - coding agents, automated review, or agentic tooling in the software development lifecycle - and an interest in helping the team adopt them well. * Experience with machine-to-machine and API authentication for third-party integrators. ## Description You will work across the partner authentication estate: the services that broker authentication flows, the long-lived systems that still carry production traffic, the identity platform they run against, and the integrations that hundreds of downstream consumers depend on. Ownership here is of problems and outcomes rather than a fixed component - what you hold changes as the migration moves, and engineers on this team are expected to follow the work rather than defend a boundary., * Build and operate backend services across partner authentication. Design, build, run, and evolve services that broker authentication between Booking.com's partner systems and the identity provider - their data models, APIs, caching and consistency behaviour, and failure modes - taking full ownership of what you ship. * Deliver migration workstreams. Design and execute phased cutovers of partner authentication from the legacy Perl stack to Auth0 - coexistence strategies, dual-write and reconciliation paths, staged rollouts, and rollback plans that hold under live traffic. * Maintain and change the legacy estate. Read, debug, and safely modify long-lived Perl services that still carry production authentication traffic, and progressively reduce our dependency on them. * Configure and extend the identity platform. Implement authentication and authorization behaviour in Auth0 - tenant and application configuration, custom logic in the authentication pipeline, connection and directory strategy, token and session design - and encode that configuration as reviewable, versioned artifacts rather than console changes. * Lead technical investigations. Act as a primary investigator for login-path incidents and anomalies spanning our services, the identity provider, edge infrastructure, and partner integrations. Drive these to root cause, write them up, and turn findings into changes. * Measure changes on real traffic. Instrument authentication flows, define and defend the metrics that describe login health, and run controlled experiments to validate that migration steps are neutral or positive for partners. * Support the wider team and its consumers. Act as a go-to technical reference on partner identity for engineers inside and outside PIAM: unblock integrations, review designs that touch authentication, and raise the team's collective understanding of the domain. * Participate in on-call for services with a direct partner-visible blast radius. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Travel’s AI-Powered Shift: How Expedia Group Is Building in the AI Era](https://www.wearedevelopers.com/videos/100430-travel-s-ai-powered-shift-how-expedia-group-is-building-in-the-ai-era) - [Developing the Backend with Stefan Lingler, CTO at Shpock](https://www.wearedevelopers.com/videos/100360-developing-the-backend-with-stefan-lingler-cto-at-shpock) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [It passed auth, then production caught fire](https://www.wearedevelopers.com/videos/100499-it-passed-auth-then-production-caught-fire) - [Nest.js - TypeScript in the backend can also be clean](https://www.wearedevelopers.com/videos/1033-nest-js-typescript-in-the-backend-can-also-be-clean) ## Related Articles - [How to land a developer job in Amsterdam](https://www.wearedevelopers.com/magazine/36-how-to-land-a-developer-job-in-amsterdam) - [Highest Paying Tech Companies in Europe](https://www.wearedevelopers.com/magazine/162-highest-paying-tech-companies-in-europe) - [How to Find Tech Jobs in Amsterdam](https://www.wearedevelopers.com/magazine/279-how-to-find-tech-jobs-in-amsterdam) - [Software Developer Salary in The Netherlands [2023]](https://www.wearedevelopers.com/magazine/217-software-developer-salary-in-the-netherlands-2023) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs)