
Trend Micro
Jul 2024 - Present · 2 yrs 3 mos
Taiwan Taipei · Hybrid
Senior Software Engineer
Full-time
Jan 2026 - Present
Leading FIPS 140-3 and STIG compliance engineering for Trend Micro's Vision One Container Security (Sovereign Private Cloud), combining Compliance-as-Code automation with AI-assisted tooling.
- Migrated infrastructure-scope images to ChainGuard FIPS 140-3 compliant versions alongside colleagues within 5 weeks
- Compliance as Code: automated FIPS compliance and STIG scanning workflows, cutting information lag from 7 days to under 30 minutes
- Refactored Helm Charts to align with STIG compliance, achieving rigorous federal-grade security baselines
- Reduced deployment friction by documenting common FIPS 140-3 compliance patterns and troubleshooting guides for 80+ stakeholder teams
- Leveraged Claude AI skills to package FIPS/STIG migration guidance, accelerating developer adoption across Docker images and Helm Charts
- Automated hardened image migrations and CVE remediation by integrating Claude Code into GitHub Actions, reducing manual engineering effort by 40% while autonomously validating Helm charts, committing changes, and deploying patches to test environments
Software Engineer
Full-time
Jul 2024 - Dec 2025
Owned the ASSESSMENTS module end-to-end as a full-cycle developer, from planning and design through implementation, testing, deployment, and operations.
- Designed an isolated worker node for data synchronization, enabling real-time access and increasing operational efficiency by 40%
- Improved service availability SLO from 98% to 99.9% by implementing shared Redis caching and using LLM tools to diagnose performance bottlenecks
- Leveraged AI tools (Claude Code) to automate testing, increasing coverage from 0% to 94.17% and resolving critical concurrency issues
- Re-architected core logic using Domain-Driven Design (DDD) and Azure Functions to automate partner site creation, cutting turnaround time from 2 weeks to 2 days
- Automated Azure AD secret rotation via GitHub Actions and resolved 11 critical support/PCT cases
- Collaborated with Japanese stakeholders to collect and organize evidence for ISMAP registration, ensuring alignment with official security requirements








