Posted:
7/20/2026, 6:01:57 PM
Location(s):
Taipei, Taiwan
Experience Level(s):
Junior ⋅ Mid Level
Field(s):
DevOps & Infrastructure ⋅ Software Engineering
Workplace Type:
On-site
Pay:
$90k–$111k/yr
Join Trend ‧ Join New Generation
趨勢科技 - 全球雲端資安領航者 / 全亞洲最大軟體公司 / 企業版圖橫跨五大洲 / 趨勢全球研發基地在台灣
===============================================================
## About the Team
The OAT (Observed Attack Techniques) team owns the backend platform behind XDR Threat Investigation in the Trend Vision One Platform — a Python monorepo of 65+ microservices spanning three domains: Observed Attack Techniques detection/search, an Exporting Pipeline (SIEM integrations, Splunk/S3 export), and a Custom Detection Model engine. The platform runs across Azure AKS and AWS Lambda, in four deployment variants (Commercial, SPC, TCP), serving enterprise security customers at scale.
## About the Role
We're hiring a **Mid-Level Backend Engineer (1-3 years experience)** to design and build the Python services and data pipelines that power OAT. You'll spend most of your time writing Python: implementing and evolving RESTful APIs, building the batch/streaming pipelines that process security detection events at high volume, and designing the data models and contracts those services share. Cloud deployment (AWS/Azure) is part of the job, but the core of the role is backend software engineering and infrastructure operations.
This role is a strong fit if you like designing clean APIs, reasoning about data pipeline correctness and throughput, and want to work on backend systems that process real security telemetry at scale.
## What We're Looking For
**Must-haves**
- 1-3 years of professional backend software engineering experience, primarily in **Python**
- Strong experience designing and building **RESTful APIs** (Flask, FastAPI, Django REST, or similar) — including versioning, error handling, and contract-first (OpenAPI/Swagger) development
- Experience building **data pipelines** — batch or streaming — including reasoning about correctness, idempotency, and throughput under load
- Solid understanding of relational or document databases and caching layers
- Comfortable writing and maintaining unit tests; understands testing behavior vs. implementation
**Nice-to-haves**
- Experience with Kafka or another event-streaming platform
- Experience building or operating AWS Lambda / serverless services (API Gateway, S3 event triggers, SQS, DynamoDB) — you'll use these directly, not just deploy to them
- Exposure to Kubernetes-deployed services (even just consuming/debugging them, not necessarily managing clusters) and Helm-based config
- Basic familiarity with CI/CD concepts (GitHub Actions or similar) — you'll ship through an existing pipeline, not build one
- Familiarity with security/threat-detection domain concepts (MITRE ATT&CK, SIEM, detection rules) — not required, but a plus
- Experience working across multiple product variants/feature flags in a single codebase (e.g., commercial vs. compliance-restricted deployments)
## Why This Role
- Own real backend services and pipelines in a production security platform — not a green-field toy project
- Work across the full stack of a detection pipeline: API surface, event processing, custom filter/alerting logic, and data storage
- See your code run end-to-end across two clouds (AWS Lambda + Azure AKS) and four product variants, without being on the hook for infrastructure design — great for a backend engineer who wants real cloud fluency, not just an abstraction to code against
- Clear team conventions (documented style guide, error-code standards, deployment rules, test naming) so you can focus on writing good code, not guessing conventions
===============================================================
連結智慧 守護世界 --- Connected Intelligence for Securing a Connected World
Website: https://www.trendmicro.com/
Headquarter Location: Tokyo, Japan
Employee Count: 5001-10000
Year Founded: 1988
IPO Status: Public
Industries: Cloud Security ⋅ Cyber Security ⋅ Security ⋅ Virtualization
Visa Sponsorship: Sponsors work visas