ActiveJobs

Backend / Cloud Software Engineer — XDR Threat Investigation (OAT Platform)

Trend Micro (UK) · Taipei

Full-timeOn-sitePosted 21 July 2026
Apply on Company Site →

Job description

Join Trend ‧ Join New Generation 趨勢科技 - 全球雲端資安領航者 / 全亞洲最大軟體公司 / 企業版圖橫跨五大洲 / 趨勢全球研發基地在台灣 =============================================================== ## About the Team The OAT (Observed Attack Techniques) team owns the backend platform behind XDR Threat Investigation in the Trend Vision One Platform — a Python monorepo of 65+ microservices spanning three domains: Observed Attack Techniques detection/search, an Exporting Pipeline (SIEM integrations, Splunk/S3 export), and a Custom Detection Model engine. The platform runs across Azure AKS and AWS Lambda, in four deployment variants (Commercial, SPC, TCP), serving enterprise security customers at scale. ## About the Role We're hiring a **Mid-Level Backend Engineer (1-3 years experience)** to design and build the Python services and data pipelines that power OAT. You'll spend most of your time writing Python: implementing and evolving RESTful APIs, building the batch/streaming pipelines that process security detection events at high volume, and designing the data models and contracts those services share. Cloud deployment (AWS/Azure) is part of the job, but the core of the role is backend software engineering and infrastructure operations. This role is a strong fit if you like designing clean APIs, reasoning about data pipeline correctness and throughput, and want to work on backend systems that process real security telemetry at scale. ## What We're Looking For **Must-haves** - 1-3 years of professional backend software engineering experience, primarily in **Python** - Strong experience designing and building **RESTful APIs** (Flask, FastAPI, Django REST, or similar) — including versioning, error handling, and contract-first (OpenAPI/Swagger) development - Experience building **data pipelines** — batch or streaming — including reasoning about correctness, idempotency, and throughput under load - Solid understanding of relational or document databases and caching layers - Comfortable writing and maintaining unit tests; understands testing behavior vs. implementation **Nice-to-haves** - Experience with Kafka or another event-streaming platform - Experience building or operating AWS Lambda / serverless services (API Gateway, S3 event triggers, SQS, DynamoDB) — you'll use these directly, not just deploy to them - Exposure to Kubernetes-deployed services (even just consuming/debugging them, not necessarily managing clusters) and Helm-based config - Basic familiarity with CI/CD concepts (GitHub Actions or similar) — you'll ship through an existing pipeline, not build one - Familiarity with security/threat-detection domain concepts (MITRE ATT&CK, SIEM, detection rules) — not required, but a plus - Experience working across multiple product variants/feature flags in a single codebase (e.g., commercial vs. compliance-restricted deployments) ## Why This Role - Own real backend services and pipelines in a production security platform — not a green-field toy project - Work across the full stack of a detection pipeline: API surface, event processing, custom filter/alerting logic, and data storage - See your code run end-to-end across two clouds (AWS Lambda + Azure AKS) and four product variants, without being on the hook for infrastructure design — great for a backend engineer who wants real cloud fluency, not just an abstraction to code against - Clear team conventions (documented style guide, error-code standards, deployment rules, test naming) so you can focus on writing good code, not guessing conventions =============================================================== 連結智慧 守護世界 --- Connected Intelligence for Securing a Connected World

Verified and listed by ActiveJobs. Applications are made directly on Trend Micro (UK)'s own career page — we never sit in the middle.