ActiveJobs

Staff Software Engineer

Trend Micro (UK) · Austin

Full-timeOn-sitePosted 24 August 2026
Apply on Company Site →

Job description

TrendAI™, the global AI security leader and enterprise business unit of Trend Micro, empowers organizations with full AI visibility and consolidated security that inspires confidence, drives innovation, and eliminates risk. At TrendAI™, we’re always seeking exceptional talent; people who want to collaborate with the best and push boundaries together. Here, your work goes beyond building a career. You will help protect what matters and play a vital role in shaping a safer, more trustworthy AI-powered future. AI Fearlessly. Location: This is a hybrid role based out of our Austin, TX office and requires in-office presence three days a week (Tuesday, Wednesday, Thursday). Position Summary: TrendAI is seeking a Staff or Senior Staff Software Engineer to help build Trend Vision One™ Internet Access, our secure web gateway. Internet Access sits inline between an enterprise's users and everything they reach on the internet — web, SaaS, and increasingly AI services — and applies the customer's policy to that traffic: what's allowed, what's inspected, and what data isn't permitted to leave. The Austin team works across three surfaces: a fleet of cloud proxy points of presence that inspect customer traffic in dozens of global regions across multiple clouds; a gateway that customers deploy inside their own network when traffic has to be inspected on premises; and a cloud control plane of microservices that runs policy, identity, inspection configuration, and logging. Inspection itself spans HTTPS interception, URL and cloud-application classification, data-loss prevention, and prompt and response inspection for AI services. This is a hands-on engineering role with architectural scope, and the team is taking on a materially wider slice of the product than it owns today. AI Secure Access is the fastest-moving part of it. Enterprises want to let employees use Claude, Copilot, Gemini and their coding agents without leaking source code or customer data into them, and want that traffic restricted to their own corporate tenant. Delivering that means understanding how each of those clients actually behaves on the wire — including the ways a client will route around a block it just received — and turning that into detection we can ship and test daily. How We Build: We're moving in the same direction as the rest of the industry: engineers no longer just write code; we design the systems that produce it. Concretely, we're building toward a daily loop where: Engineers work through an agent harness (Claude Code, plus its peers) layered on top of GitHub Actions, Jira, CI/CD, docs, and runtime data. Agents handle most of the inner development loop. Humans gate at the edges — architecture, end-to-end validation, the failures the agents can't resolve, and the question of what "good" actually means. Engineers design the pipeline; if the output is bad, we fix the assembly line. We're partway through this transition and the candidate we hire will help define how much further it goes. AI makes mistakes — confidently. A senior engineer's value shifts from typing code (AI does that) toward defining the right requirements, catching the plausible-but-wrong output, and bringing the context AI doesn't have. The skills that matter most: Systems thinking — catch failure modes (latency, cost, drift, silent failures) before they reach production. Operational instinct — when something looks off in production, reach for metrics, profiling, and autoscaling without waiting for an SRE. Critical review — design validation layers and catch the subtle thing that looks right but isn't. Security thinking — zero-trust is the product and the development model; reason about access control, data protection, and safe execution boundaries by default. Domain expertise — understand (or be ready to learn) our customers' environments, the problems they bring us, and the operational realities that aren't in any spec. Responsibilities: Design and implement features across the cloud proxy data path, the control-plane microservices behind it, and the gateway customers run on premises. Own one or more services end to end (policy and rule evaluation, traffic inspection, identity and directory group sync, gateway management, activity logging). Extend AI Secure Access coverage: determine how a new AI service, assistant, or coding agent behaves on the wire, define what we can identify and control, implement it, and add the automated detection tests that catch a client changing its behavior before a customer does. Diagnose and resolve performance and correctness problems in a live inspection path: latency, throughput, connection handling, memory pressure, autoscaling behavior. Write architecture proposals and design documents; drive them through review with peers and the team's architect. Investigate complex production support cases — the ones that require domain expertise about a customer's network, an interop quirk in an application that breaks under inspection, or proposing a different approach to their problem. Contribute to the team's AI-augmented development pipeline: shape what gets autonomous, where humans gate, and what validation is non-negotiable for a security product. Required Qualifications: 5+ years of experience building production backend systems for the Staff level, 7+ for Senior Staff. Equally comfortable with Kubernetes-deployed services and software that ships to a customer's own environment — our stack spans both. Strong proficiency in Go or an adjacent systems-leaning language (Rust, C++, or similar) and willingness to be polyglot in our stack (Go, C/C++, Python). Networking fundamentals at real depth — HTTP/HTTPS, forward-proxy behavior (CONNECT, PAC, proxy chaining), TLS and TLS interception, DNS, TCP/IP, NAT, firewalls. The product is an inline proxy; this is the core of it, not background knowledge. Hands-on production debugging with metrics, profiling, packet captures, and autoscaling (HPA / KEDA). Linux internals (systemd, namespaces, networking) at a level sufficient to debug a misbehaving gateway running on a customer's host. Demonstrated experience operating software that runs in customer environments — on-prem services, appliance or VM images, update mechanisms — and the realities of long-tail version compatibility (customers do not upgrade on your schedule). Demonstrated experience using an agent harness like ours in real engineering work, and the judgment to direct, review, and validate its output. Excellent written communication; ability to write design documents that survive review. Preferred Qualifications: Prior work on an SWG, SASE, SSE, CASB, DLP, or other web or network security product. Experience determining how an application protocol works from observed traffic, and building detection or enforcement on top of that understanding. Distributed systems experience — consistency, retries, idempotency, and reasoning about partial failures across services and regions. Production depth running services in AWS, where most of our proxy fleet and cloud services live. Azure, Google Cloud, and Oracle Cloud Infrastructure experience is a plus — we run points of presence in all four to meet customer latency and data-residency requirements. Depth in high-throughput content inspection or proxy internals in C or C++ (Apache Traffic Server or a comparable proxy, protocol parsers, scanning engines). Enterprise identity and directory integration: SAML, Kerberos, OIDC, and the realities of keeping user and group data in sync with a customer's directory. Experience designing or operating an LLM-powered system in production (RAG, agentic workflows, or otherwise). Track record of driving architectural decisions across multiple services and lifting peers along the way. Why Join TrendAI? TrendAI is a leader in AI security. We not only delivered the first open-weight, cybersecurity-focused large language model, but also the industry's first security companion agent e

Verified and listed by ActiveJobs. Applications are made directly on Trend Micro (UK)'s own career page — we never sit in the middle.