Backend / Cloud Software Engineer — XDR Threat Investigation (OAT Platform)

Posted:
7/20/2026, 6:01:57 PM

Location(s):
Taipei, Taiwan

Experience Level(s):
Junior ⋅ Mid Level

Field(s):
DevOps & Infrastructure ⋅ Software Engineering

Workplace Type:
On-site

Pay:
$90k–$111k/yr

Join Trend ‧ Join New Generation

趨勢科技 - 全球雲端資安領航者 / 全亞洲最大軟體公司 / 企業版圖橫跨五大洲 / 趨勢全球研發基地在台灣 
===============================================================

## About the Team

The OAT (Observed Attack Techniques) team owns the backend platform behind XDR Threat Investigation in the Trend Vision One Platform — a Python monorepo of 65+ microservices spanning three domains: Observed Attack Techniques detection/search, an Exporting Pipeline (SIEM integrations, Splunk/S3 export), and a Custom Detection Model engine. The platform runs across Azure AKS and AWS Lambda, in four deployment variants (Commercial, SPC, TCP), serving enterprise security customers at scale.

## About the Role

We're hiring a **Mid-Level Backend Engineer (1-3 years experience)** to design and build the Python services and data pipelines that power OAT. You'll spend most of your time writing Python: implementing and evolving RESTful APIs, building the batch/streaming pipelines that process security detection events at high volume, and designing the data models and contracts those services share. Cloud deployment (AWS/Azure) is part of the job, but the core of the role is backend software engineering and infrastructure operations.

This role is a strong fit if you like designing clean APIs, reasoning about data pipeline correctness and throughput, and want to work on backend systems that process real security telemetry at scale.

## What We're Looking For

**Must-haves**

- 1-3 years of professional backend software engineering experience, primarily in **Python**

- Strong experience designing and building **RESTful APIs** (Flask, FastAPI, Django REST, or similar) — including versioning, error handling, and contract-first (OpenAPI/Swagger) development

- Experience building **data pipelines** — batch or streaming — including reasoning about correctness, idempotency, and throughput under load

- Solid understanding of relational or document databases and caching layers

- Comfortable writing and maintaining unit tests; understands testing behavior vs. implementation

**Nice-to-haves**

- Experience with Kafka or another event-streaming platform

- Experience building or operating AWS Lambda / serverless services (API Gateway, S3 event triggers, SQS, DynamoDB) — you'll use these directly, not just deploy to them

- Exposure to Kubernetes-deployed services (even just consuming/debugging them, not necessarily managing clusters) and Helm-based config

- Basic familiarity with CI/CD concepts (GitHub Actions or similar) — you'll ship through an existing pipeline, not build one

- Familiarity with security/threat-detection domain concepts (MITRE ATT&CK, SIEM, detection rules) — not required, but a plus

- Experience working across multiple product variants/feature flags in a single codebase (e.g., commercial vs. compliance-restricted deployments)

## Why This Role

- Own real backend services and pipelines in a production security platform — not a green-field toy project

- Work across the full stack of a detection pipeline: API surface, event processing, custom filter/alerting logic, and data storage

- See your code run end-to-end across two clouds (AWS Lambda + Azure AKS) and four product variants, without being on the hook for infrastructure design — great for a backend engineer who wants real cloud fluency, not just an abstraction to code against

- Clear team conventions (documented style guide, error-code standards, deployment rules, test naming) so you can focus on writing good code, not guessing conventions

===============================================================
連結智慧 守護世界 --- Connected Intelligence for Securing a Connected World