Join Trend ‧ Join New Generation
趨勢科技 - 全球雲端資安領航者 / 全亞洲最大軟體公司 / 企業版圖橫跨五大洲 / 趨勢全球研發基地在台灣
===============================================================
## About the Team
The OAT (Observed Attack Techniques) team owns the backend platform behind XDR Threat Investigation in the Trend Vision One Platform — a Python monorepo of 65+ microservices spanning three domains: Observed Attack Techniques detection/search, an Exporting Pipeline (SIEM integrations, Splunk/S3 export), and a Custom Detection Model engine. The platform runs across Azure AKS and AWS Lambda, in four deployment variants (Commercial, SPC, TCP), serving enterprise security customers at scale.
## About the Role
We're hiring a **Mid-Level Backend Engineer (1-3 years experience)** to design and build the Python services and data pipelines that power OAT. You'll spend most of your time writing Python: implementing and evolving RESTful APIs, building the batch/streaming pipelines that process security detection events at high volume, and designing the data models and contracts those services share. Cloud deployment (AWS/Azure) is part of the job, but the core of the role is backend software engineering and infrastructure operations.
This role is a strong fit if you like designing clean APIs, reasoning about data pipeline correctness and throughput, and want to work on backend systems that process real security telemetry at scale.
## What We're Looking For
**Must-haves**
- 1-3 years of professional backend software engineering experience, primarily in **Python**
- Strong experience designing and building **RESTful APIs** (Flask, FastAPI, Django REST, or similar) — including versioning, error handling, and contract-first (OpenAPI/Swagger) development
- Experience building **data pipelines** — batch or streaming — including reasoning about correctness, idempotency, and throughput under load
- Solid understanding of relational or document databases and caching layers
- Comfortable writing and maintaining unit tests; understands testing behavior vs. implementation
**Nice-to-haves**
- Experience with Kafka or another event-streaming platform
- Experience building or operating AWS Lambda / serverless services (API Gateway, S3 event triggers, SQS, DynamoDB) — you'll use these directly, not just deploy to them
- Exposure to Kubernetes-deployed services (even just consuming/debugging them, not necessarily managing clusters) and Helm-based config
- Basic familiarity with CI/CD concepts (GitHub Actions or similar) — you'll ship through an existing pipeline, not build one
- Familiarity with security/threat-detection domain concepts (MITRE ATT&CK, SIEM, detection rules) — not required, but a plus
- Experience working across multiple product variants/feature flags in a single codebase (e.g., commercial vs. compliance-restricted deployments)
## Why This Role
- Own real backend services and pipelines in a production security platform — not a green-field toy project
- Work across the full stack of a detection pipeline: API surface, event processing, custom filter/alerting logic, and data storage
- See your code run end-to-end across two clouds (AWS Lambda + Azure AKS) and four product variants, without being on the hook for infrastructure design — great for a backend engineer who wants real cloud fluency, not just an abstraction to code against
- Clear team conventions (documented style guide, error-code standards, deployment rules, test naming) so you can focus on writing good code, not guessing conventions
===============================================================
連結智慧 守護世界 --- Connected Intelligence for Securing a Connected World
Skills Required
- 1-3 years professional backend software engineering experience, primarily in Python
- Strong experience designing and building RESTful APIs (Flask, FastAPI, Django REST, OpenAPI/Swagger)
- Experience building data pipelines (batch or streaming) with focus on correctness, idempotency, and throughput
- Solid understanding of relational or document databases and caching layers
- Comfortable writing and maintaining unit tests; testing behavior vs implementation
- Experience with Kafka or another event-streaming platform
- Experience building or operating AWS Lambda / serverless services (API Gateway, S3 event triggers, SQS, DynamoDB)
- Exposure to Kubernetes-deployed services and Helm-based configuration
- Basic familiarity with CI/CD concepts (GitHub Actions or similar)
- Familiarity with security/threat-detection domain concepts (MITRE ATT&CK, SIEM, detection rules)
- Experience working across multiple product variants/feature flags in a single codebase
What We Do
We’re a global cybersecurity leader, helping to make the world safe for exchanging digital information. Fueled by decades of security expertise, global threat research, and continuous innovation, our cybersecurity platform protects hundreds of thousands of organizations and millions of individuals across clouds, networks, devices, and endpoints. As a leader in cloud and enterprise cybersecurity, our platform delivers a powerful range of advanced threat defense techniques optimized for environments like AWS, Microsoft, and Google, and central visibility for better, faster detection and response. Our global threat research team delivers unparalleled intelligence and insights that power our cybersecurity platform and help protect organizations around the world from 100s of millions of threats daily. We have 7,000 employees across 65 countries, singularly focused on security and passionate about making the world a safer and better place. We enable organizations to simplify and secure their connected world. Trend Micro’s “Trenders” are passionate about doing the right thing to make the world a safer and better place.









