Trend Micro

Backend / Cloud Software Engineer — XDR Threat Investigation (OAT Platform)

Trend Micro  •  Taipei, TW (Onsite)  •  10 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

Join Trend ‧ Join New Generation

趨勢科技 - 全球雲端資安領航者 / 全亞洲最大軟體公司 / 企業版圖橫跨五大洲 / 趨勢全球研發基地在台灣
===============================================================

## About the Team

The OAT (Observed Attack Techniques) team owns the backend platform behind XDR Threat Investigation in the Trend Vision One Platform — a Python monorepo of 65+ microservices spanning three domains: Observed Attack Techniques detection/search, an Exporting Pipeline (SIEM integrations, Splunk/S3 export), and a Custom Detection Model engine. The platform runs across Azure AKS and AWS Lambda, in four deployment variants (Commercial, SPC, TCP), serving enterprise security customers at scale.

## About the Role

We're hiring a **Mid-Level Backend Engineer (1-3 years experience)** to design and build the Python services and data pipelines that power OAT. You'll spend most of your time writing Python: implementing and evolving RESTful APIs, building the batch/streaming pipelines that process security detection events at high volume, and designing the data models and contracts those services share. Cloud deployment (AWS/Azure) is part of the job, but the core of the role is backend software engineering and infrastructure operations.

This role is a strong fit if you like designing clean APIs, reasoning about data pipeline correctness and throughput, and want to work on backend systems that process real security telemetry at scale.

## What We're Looking For

**Must-haves**

- 1-3 years of professional backend software engineering experience, primarily in **Python**

- Strong experience designing and building **RESTful APIs** (Flask, FastAPI, Django REST, or similar) — including versioning, error handling, and contract-first (OpenAPI/Swagger) development

- Experience building **data pipelines** — batch or streaming — including reasoning about correctness, idempotency, and throughput under load

- Solid understanding of relational or document databases and caching layers

- Comfortable writing and maintaining unit tests; understands testing behavior vs. implementation

**Nice-to-haves**

- Experience with Kafka or another event-streaming platform

- Experience building or operating AWS Lambda / serverless services (API Gateway, S3 event triggers, SQS, DynamoDB) — you'll use these directly, not just deploy to them

- Exposure to Kubernetes-deployed services (even just consuming/debugging them, not necessarily managing clusters) and Helm-based config

- Basic familiarity with CI/CD concepts (GitHub Actions or similar) — you'll ship through an existing pipeline, not build one

- Familiarity with security/threat-detection domain concepts (MITRE ATT&CK, SIEM, detection rules) — not required, but a plus

- Experience working across multiple product variants/feature flags in a single codebase (e.g., commercial vs. compliance-restricted deployments)

## Why This Role

- Own real backend services and pipelines in a production security platform — not a green-field toy project

- Work across the full stack of a detection pipeline: API surface, event processing, custom filter/alerting logic, and data storage

- See your code run end-to-end across two clouds (AWS Lambda + Azure AKS) and four product variants, without being on the hook for infrastructure design — great for a backend engineer who wants real cloud fluency, not just an abstraction to code against

- Clear team conventions (documented style guide, error-code standards, deployment rules, test naming) so you can focus on writing good code, not guessing conventions

===============================================================
連結智慧 守護世界 --- Connected Intelligence for Securing a Connected World

Trend Micro

About Trend Micro

Trend Micro, a global cybersecurity leader, helps make the world safe for exchanging digital information across enterprises, governments, and consumers.

Fueled by decades of security expertise and relentless innovation, Trend leverages the full power of AI to protect over 500,000 enterprises and millions of individuals across clouds, networks, endpoints, and devices.

At the core of this protection is Trend Vision One™, the only AI-powered enterprise cybersecurity platform that centralizes cyber risk exposure management and security operations, delivering robust layered protection across on-premises, hybrid, and multi-cloud environments.

This platform is fueled by world-class threat intelligence and insights that help defend organizations from hundreds of millions of threats every day.

With 7,000 employees across 70 countries, Trend empowers security leaders to stay ahead of threats, driving proactive security outcomes across the entire attack surface. This includes critical environments like AWS, Google, Microsoft, and NVIDIA.

Proactive security starts here.

Industry
IT & Software
Company Size
5,001-10,000 employees
Headquarters
Tokyo, JP
Year Founded
Unknown
Social Media