Search by job, company or skills

Backend / Cloud Software Engineer — XDR Threat Investigation (OAT Platform)

1-3 Years
  • Posted 5 hours ago
  • Be among the first 10 applicants

Job Description

Join Trend ‧ Join New Generation

趨勢科技 - 全球雲端資安領航者 / 全亞洲最大軟體公司 / 企業版圖橫跨五大洲 / 趨勢全球研發基地在台灣
===============================================================

## About the Team

The OAT (Observed Attack Techniques) team owns the backend platform behind XDR Threat Investigation in the Trend Vision One Platform - a Python monorepo of 65+ microservices spanning three domains: Observed Attack Techniques detection/search, an Exporting Pipeline (SIEM integrations, Splunk/S3 export), and a Custom Detection Model engine. The platform runs across Azure AKS and AWS Lambda, in four deployment variants (Commercial, SPC, TCP), serving enterprise security customers at scale.

## About the Role

We're hiring a ..Mid-Level Backend Engineer (1-3 years experience).. to design and build the Python services and data pipelines that power OAT. You'll spend most of your time writing Python: implementing and evolving RESTful APIs, building the batch/streaming pipelines that process security detection events at high volume, and designing the data models and contracts those services share. Cloud deployment (AWS/Azure) is part of the job, but the core of the role is backend software engineering and infrastructure operations.

This role is a strong fit if you like designing clean APIs, reasoning about data pipeline correctness and throughput, and want to work on backend systems that process real security telemetry at scale.

## What We're Looking For

..Must-haves..

- 1-3 years of professional backend software engineering experience, primarily in ..Python..

- Strong experience designing and building ..RESTful APIs.. (Flask, FastAPI, Django REST, or similar) - including versioning, error handling, and contract-first (OpenAPI/Swagger) development

- Experience building ..data pipelines.. - batch or streaming - including reasoning about correctness, idempotency, and throughput under load

- Solid understanding of relational or document databases and caching layers

- Comfortable writing and maintaining unit tests understands testing behavior vs. implementation

..Nice-to-haves..

- Experience with Kafka or another event-streaming platform

- Experience building or operating AWS Lambda / serverless services (API Gateway, S3 event triggers, SQS, DynamoDB) - you'll use these directly, not just deploy to them

- Exposure to Kubernetes-deployed services (even just consuming/debugging them, not necessarily managing clusters) and Helm-based config

- Basic familiarity with CI/CD concepts (GitHub Actions or similar) - you'll ship through an existing pipeline, not build one

- Familiarity with security/threat-detection domain concepts (MITRE ATT&CK, SIEM, detection rules) - not required, but a plus

- Experience working across multiple product variants/feature flags in a single codebase (e.g., commercial vs. compliance-restricted deployments)

## Why This Role

- Own real backend services and pipelines in a production security platform - not a green-field toy project

- Work across the full stack of a detection pipeline: API surface, event processing, custom filter/alerting logic, and data storage

- See your code run end-to-end across two clouds (AWS Lambda + Azure AKS) and four product variants, without being on the hook for infrastructure design - great for a backend engineer who wants real cloud fluency, not just an abstraction to code against

- Clear team conventions (documented style guide, error-code standards, deployment rules, test naming) so you can focus on writing good code, not guessing conventions

===============================================================

More Info

Job ID: 152617335

Beware of Scammers

We don’t charge money for job offers