Full-Time

Technical Consultant

Trellix

Trellix

1,001-5,000 employees

XDR security platform for threat detection

No salary listed

Bengaluru, Karnataka, India

Hybrid

Hybrid role; some on-site presence in Bengaluru, India.

Category
Consulting (1)
Required Skills
Microsoft Azure
Computer Networking
AWS
Google Cloud Platform

Get referred to Trellix

See people who can refer or advise you

Requirements
  • 7 to 10+ years of experience in a customer-facing technical role (Technical Consultant, Solution Architect, Technical Account Manager, Sales Engineer, or similar)
  • Ready to work on permanent EST shift
  • Strong background in network security, cloud security, and SSE/SASE solutions
  • Experience with firewalls, proxies, CASB, DLP, Zero Trust Network Access (ZTNA), and Secure Web Gateway (SWG)
  • Proficiency in network protocols, authentication mechanisms, and security frameworks
  • Hands-on experience with cloud platforms such as AWS, Azure, or Google Cloud
  • Strong troubleshooting and problem-solving skills with a customer-first mindset
  • Excellent communication and presentation skills, with the ability to translate technical concepts for various audiences
  • Experience coaching and training customers to use technical products effectively
  • Ability to manage multiple accounts while prioritizing key customer needs
Responsibilities
  • Implement Secure Web Gateway, Cloud Access Security Broker, Zero Trust Network Access, Data Loss Prevention, and other Secure Software Edge security solutions based on the Solution Architect’s design
  • Configure security policies, user access controls, and enterprise integrations
  • Perform policy migration and optimization to ensure compliance and best practices
  • Conduct pilot testing, user acceptance testing, and final production rollout
  • Deliver technical training and enablement to customer teams to effectively manage the product
  • Provide ongoing technical guidance and troubleshooting support for complex issues
  • Lead best practice workshops and enablement sessions to upskill customer teams
  • Provide continuous education and coaching to customers on existing and new features to ensure they maximize the value of the solution
  • Provide context and help to the Support team to ensure that service requests are addressed and effectively communicated to the customer
  • Manage and escalate customer concerns internally when necessary
  • Act as the technical point of contact post-deployment, ensuring customers fully adopt, optimize, and expand their SSE solution
  • Monitor solution performance, adoption and provide proactive recommendations to improve efficiency, security, and compliance
  • Participate in business reviews and conduct technical health checks to track progress and address gaps
  • Identify opportunities for expansion by assessing additional use cases, security
  • Assist with change management and internal advocacy within customer teams to drive long-term adoption
  • Collaborate with Customer Success Manager, Sales, and Product teams to align solutions with customer objectives
  • Document deployment procedures, configuration settings, and optimization strategies
  • Contribute to the internal knowledge base for Professional Services and Technical Account Management best practices
  • Mentor and coach other Technical Consultants and Technical Account Managers to enhance team expertise
  • Contribute to internal knowledge-sharing initiatives, training programs, and best practice discussions
  • Provide feedback on customer pain points and feature requests to Product and Engineering teams
  • Stay up to date with industry security trends, emerging threats, and SSE product advancements
Desired Qualifications
  • Industry certifications such as CCNA Security, CompTIA Security+, AWS/Azure Security, CCSK/CCSP or CISSP
  • Experience working with large enterprise customers and managing multi-region deployments
  • Experience working with Professional Services Automation tools (OpenAir, FinancialForce)
  • Customer Value Career Path

Trellix provides an extended detection and response (XDR) platform that integrates endpoint, network, and cloud security into a single system. The platform works by using Generative AI and threat intelligence to help security teams detect and respond to cyberattacks across their entire digital infrastructure. Unlike many competitors that offer isolated security tools, Trellix uses an "open" architecture that allows its software to connect with a wide variety of third-party applications and hardware. The company's goal is to provide organizations with a unified, automated defense system that simplifies how they manage and resolve complex security threats.

Company Size

1,001-5,000

Company Stage

Growth Equity (Venture Capital)

Total Funding

$435M

Headquarters

Plano, Texas

Founded

2021

Get referred to Trellix

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Joe Chen became CTO on 2026-05-19, strengthening engineering execution and roadmap discipline.
  • On 2026-04-08, Trellix launched AI data security controls for sanctioned and shadow AI.
  • Magenta Buyer raised $400 million in 2024, extending maturities and improving liquidity.

What critics are saying

  • On 2026-07-15, Trellix disclosed source-code repository access, threatening future detection evasion.
  • Trellix headcount fell to 3,867 in March 2026, signaling ongoing operating pressure.
  • If attackers weaponize stolen code, Fortune 500 customers churn before 2027 renewals.

What makes Trellix unique

  • Trellix unifies endpoint, network, email, database, DLP, and XDR controls in one platform.
  • Its Trellix NDR and Nozomi integration gives rare OT-IT visibility across air-gapped environments.
  • Thirty years of McAfee and FireEye threat intelligence power its detection engine and response workflows.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

401(k) Retirement Plan

Paid Vacation

Paid Parental Leave

Flexible Work Hours

Growth & Insights and Company News

Headcount

6 month growth

13%

1 year growth

13%

2 year growth

-2%
Trellix
May 19th, 2026
Trellix appoints Joe Chen as Chief Technology Officer.

Trellix appoints Joe Chen as Chief Technology Officer. Cybersecurity veteran to lead mission-critical technology roadmap and harden R&D processes for the modern threat landscape SAN JOSE, Calif. - Trellix, a global leader in intelligence-led cyber resilience, today announced the appointment of Joe Chen as Chief Technology Officer. Chen will advance Trellix's mission-critical cybersecurity vision, strengthen engineering execution, and lead the next phase of the company's technology roadmap. Chen brings more than 25 years of experience driving product portfolio transformation for global cybersecurity providers. Chen will partner closely with Alex Au Yeung, Chief Product Officer, to deliver next-generation security technology for the era of AI and frontier models. The duo shares a successful history of product portfolio transformations, evolving complex, multi-product offerings into unified solutions that advance customer outcomes through clear roadmaps and rapid development cycles. "Joe is a proven technology leader who excels at simplifying complex solutions and delivering innovation at scale," said Vishal Rao, CEO of Trellix. "He brings the cybersecurity expertise, disciplined execution, and AI-forward disposition required to relentlessly strengthen our security posture and R&D processes for the modern world. I also want to thank Steve Tait for his steady leadership as interim CTO and for ensuring continuity during this transition." Chen joins Trellix at a critical moment, with a priority focus on optimizing the processes used to securely deliver high-quality innovations to the market. His leadership will reinforce the systems and practices that underpin secure product development, ensuring Trellix remains at the forefront of cyber resilience. "Cybersecurity is at an inflection point, with today's threat landscape and the rise of AI and frontier models demanding uncompromising security in everything we do," said Chen. "I'm thrilled to be joining Trellix at this pivotal time, with a sharp focus on hardening our R&D engine and applying a continuous improvement mindset to engineering operations, so we deliver the most secure, reliable, and innovative solutions to our customers at speed." Prior to Trellix, Chen was an Operating Partner at Crosspoint Capital, focusing on engineering transformation. He previously held senior leadership roles at Broadcom's Symantec Enterprise Division and Carbon Black, overseeing large-scale integration and security product development. Chen is a founding member of the Cyber Threat Alliance and holds more than 55 U.S. patents. About Trellix Trellix is a global cybersecurity company delivering intelligence-led cyber resilience for security-conscious organizations at any stage of their journey. Transforming over 30 years of threat intelligence into high-fidelity detections and automating AI-driven detection and response across cloud, on-premises, air-gapped, and operational technology environments, Trellix helps customers adapt to the constantly evolving threat landscape. More at https://trellix.com. Follow Trellix on LinkedIn and X.

Digital Forensics Magazine
May 8th, 2026
NEWS ROUNDUP - 8th may 2026.

NEWS ROUNDUP - 8th may 2026. Digital Forensics Magazine - 48h News Roundup Window: 06-05-2026 to 08-05-2026 (UTC) Snapshot summary. | Sector / Section | Headline Highlights | Count | | Digital Investigations | API exposure and source-code review | 2 | | Cyber Investigations | Supply-chain and firewall probes | 2 | | Major Cyber Incidents | Education and platform breaches | 2 | | Exploits & Threat Intelligence | Ivanti and Linux exploitation | 2 | | Law Enforcement | DPRK fraud and database deletion | 2 | | Policy & Standards | PNT and enterprise advisories | 2 | Digital Investigations. A DOD contractor API flaw exposed service-member and course data in the United States after researchers found accessible records and confidential military training material on Schemata's AI platform [AMER]. The investigative value sits in the exposed identifiers, base assignments, course metadata and patched endpoint trail, which give auditors a clear path for scope validation and third-party control review (Source: CyberScoop, 06-05-2026). Trellix confirmed unauthorised access to part of its source-code repository after a breach investigation involving external security specialists and notifications to authorities [AMER]. The company said there was no evidence that source-code distribution had been affected, leaving investigators to resolve access method, exfiltration scope, actor identity and whether any downstream abuse indicators exist (Source: TechRadar, 06-05-2026). Cyber Investigations. Kaspersky reported a DAEMON Tools supply-chain compromise after attackers replaced signed installers with trojanised builds distributed through the vendor's official channel across more than 100 countries [Global]. The staged infection chain collected host data before selectively deploying a backdoor, giving investigators file-signing artefacts, download timelines and victim-sector clustering across government, scientific, industrial and retail environments (Source: Kaspersky, 05-05-2026). Unit 42 detailed exploitation of a PAN-OS captive-portal zero-day affecting exposed Palo Alto Networks firewall authentication portals, with activity carrying indicators consistent with targeted intrusion operations [Global]. The investigation centres on unauthenticated remote code execution, affected portal exposure, root-level device access and the collection of network-edge evidence needed to determine lateral movement risk (Source: Unit 42, 07-05-2026). Major Cyber Incidents. Vimeo user data was exposed through a third-party analytics integration, with Have I Been Pwned reporting names and email addresses for about 119,000 people after ShinyHunters leaked stolen data [AMER]. The incident illustrates how technical metadata, account identifiers and integration access logs become central evidence when breach scope depends on a connected supplier rather than the primary platform alone (Source: TechRadar, 07-05-2026). Queensland education authorities confirmed student and teacher data was stolen from the Canvas-linked QLearn environment, affecting current and former users since 2020 [APAC]. Investigators are correlating provider notifications, school communications, exposed names, email addresses and school-location records while assessing risk for protected families and individuals affected by domestic violence or child-safety concerns (Source: The Courier-Mail, 07-05-2026). Exploits & Threat Intelligence. Ivanti issued fixes for EPMM vulnerabilities, including CVE-2026-6973, after warning that the flaw had been exploited in limited attacks against mobile endpoint management infrastructure [Global]. The threat picture requires administrators to preserve appliance logs, review administrator-session history, validate exposed management surfaces and confirm upgrades to fixed versions 12.6.1.1, 12.7.0.1 or 12.8.0.1 (Source: Ivanti, 07-05-2026). A Linux zero-day dubbed Dirty Frag was disclosed, with reporting that local attackers can obtain root privileges on major distributions using a public proof-of-concept exploit [Global]. Forensic triage should prioritise privilege-escalation artefacts, unusual local command execution, kernel-version exposure and whether the exploit was chained after credential theft or web-shell access (Source: BleepingComputer, 08-05-2026). Law Enforcement. Two U.S. nationals were sentenced for facilitating fraudulent remote IT worker schemes that helped North Korean workers access U.S. companies through laptop farms [AMER]. Court records describe shipped victim laptops, unauthorised remote-desktop installations, network access and revenue flows, providing a clear evidential chain from physical devices to identity deception and sanctioned state funding (Source: U.S. Department of Justice, 06-05-2026). A federal jury convicted a Virginia man over deletion of U.S. government databases, in a case involving unauthorised data destruction affecting public-sector systems [AMER]. The prosecution highlights evidential dependence on database activity records, access authorisation history, deletion timelines and system-recovery analysis when courts must distinguish administrative access from criminal misuse (Source: U.S. Department of Justice, 07-05-2026). Policy & Standards. NIST published an initial public draft of IR 8323 Revision 2, updating the Foundational PNT Profile for applying the Cybersecurity Framework 2.0 to positioning, navigation and timing services [AMER]. The draft supports evidence-led risk management by mapping functions, categories and outcomes to systems whose timing and location dependencies underpin telecommunications, finance, transport and critical infrastructure operations (Source: NIST, 06-05-2026). The Canadian Centre for Cyber Security issued Cisco advisory AV26-430 after Cisco published fixes for vulnerabilities across multiple enterprise products [AMER]. The advisory gives defenders a standards-aligned reference point for change control, patch evidence, exposure assessment and audit documentation where code execution, server-side request forgery or denial-of-service conditions could affect enterprise infrastructure (Source: Canadian Centre for Cyber Security, 06-05-2026). Editorial perspective. This cycle shows why digital investigations must treat identity, supplier access and platform telemetry as a single evidential environment. The most useful artefacts are no longer confined to endpoint images or server logs; they include integration records, administrator sessions, signed installer provenance, API exposure histories and third-party notification trails. Investigative readiness therefore depends on organisations being able to preserve cross-platform evidence before containment actions overwrite the sequence of events. The strongest operational theme is correlation: linking exposed personal data to supplier pathways, linking appliance exploitation to edge-device configuration, and linking remote-access infrastructure to physical devices and payment flows. Attribution capability remains fragile where actors use compromised software distribution or legitimate management tools, so investigators need defensible timelines and corroborated artefacts rather than assumptions based on victim sector alone. Evidence integrity will increasingly depend on structured logging, rapid legal preservation and supplier contracts that make forensic access explicit. Reference reading. Digital Investigations, API Exposure, Supply Chain Compromise, ShinyHunters, Ivanti EPMM, PAN-OS, Linux Zero-Day, North Korea IT Workers, NIST CSF, Evidence Integrity

Entivel Pty Ltd
May 5th, 2026
Analyzing the Trellix breach: mitigating vendor source code breach implications in global supply chains.

Analyzing the Trellix breach: mitigating vendor source code breach implications in global supply chains. The Trellix breach is a critical warning for global businesses. Learn about the severe vendor source code breach implications and implement actionable strategies to secure your entire software supply chain against third-party risks. The news of a significant source code repository breach at cybersecurity firm Trellix serves as more than just a headline; it is a profound warning signal to the global business community. For organizations that rely heavily on sophisticated, third-party software,from cloud infrastructure to proprietary AI tools,the potential attack surface has expanded far beyond the company's own perimeter. TL;DR: A source code breach at a major vendor like Trellix underscores that even industry leaders are vulnerable to supply chain attacks. The primary risk is not just data theft, but the potential for malicious backdoors or compromised updates being delivered directly into your operational environment. Immediate action requires rigorous third-party vendor security assessment and implementing zero-trust principles across all connected systems. Understanding vendor source code breach implications. When a company like Trellix reports unauthorized access to its source code repository, the immediate fear is that their intellectual property has been compromised. However, for international businesses, the concern runs deeper than IP theft; it speaks directly to vendor source code breach implications across your entire operational ecosystem. Source code is the blueprint of a product. If an attacker gains access, they can potentially identify logical flaws, backdoors, or even harvest details about how the software integrates with other systems,details that are far more valuable than simple customer data. This elevates the risk from a mere security incident to a critical supply chain cybersecurity risks event. Why does vendor code matter so much? Most modern enterprises do not build every piece of software internally. They consume it. Whether you use SaaS platforms, integrated cloud services, or specialized AI models provided by external vendors, your digital life is built on third-party code. If the foundation (the vendor) is compromised, the entire structure is at risk. The key challenge for IT managers today is moving beyond perimeter defense and addressing systemic trust gaps. This requires a shift in focus from simply auditing compliance reports to actively verifying security posture and validating secure code repositories in enterprise environments. Software supply chain attack mitigation strategies. Mitigating risk when dealing with massive, interconnected software ecosystems demands proactive governance. Here are the critical areas international businesses must address immediately: * Dependency Mapping: Do not assume you know every piece of code running in your environment. Map out all third-party libraries and services to identify single points of failure. * Code Validation Protocols: Implement continuous validation that goes beyond simple patch management. This involves testing updates against known attack vectors and ensuring the integrity of the deployment pipeline itself. * Segmentation and Isolation (Zero Trust): Adopt a zero-trust architecture where no vendor, internal or external, is implicitly trusted simply because they are connected to the network. Access must be granted on a least-privilege basis. The critical role of third-party vendor security assessment. A robust third-party vendor security assessment cannot be completed with a simple annual questionnaire. To properly assess the risk, organizations must perform deep cybersecurity due diligence that includes: * Reviewing the vendor's incident response plan and their history of breaches. * Verifying their controls for secrets management (e.g., API keys, access tokens). * Asking pointed questions about their development lifecycle security (DevSecOps) practices, specifically how they handle code repository access and employee offboarding. Security risk is not limited to the IT department. Understanding operational vulnerabilities helps build resilience across the entire organization. Cybersecurity tips. Implement mandatory Multi-Factor Authentication (MFA) for all vendor portals and critical services. Regularly audit API keys, treating them as highly sensitive credentials that must be rotated frequently. Business technology tips. Establish clear contractual clauses with vendors regarding breach notification timelines and liability in the event of a supply chain attack. This formalizes accountability when disaster strikes. AI tips. When adopting AI solutions, prioritize tools that offer explainability (XAI) and robust data lineage tracking. Never feed proprietary or highly sensitive internal code into an unvetted third-party model without strict contractual controls. Entivel perspective: turning this into safer growth. The Trellix incident illustrates a fundamental truth of modern business: security is no longer a standalone function; it is a core component of business resilience. For international companies looking to accelerate digital transformation through automation and AI, the risk associated with vendor dependencies must be managed proactively. At Entivel, Entivel Pty specialize in bridging this gap by embedding advanced cybersecurity measures directly into your software development life cycle (SDLC). Its approach focuses on: * Secure Code Integration: Ensuring that any new automation or AI module built using third-party components is validated and hardened against supply chain risks. * Automated Risk Monitoring: Using advanced monitoring tools to continuously assess the security posture of your connected cloud services, providing real-time alerts when a vendor's known vulnerability could impact your operations. * Digital Resilience Planning: Moving beyond compliance checklists to build actionable recovery plans that assume failure is inevitable, minimizing downtime and data exposure. By treating every third-party integration as a potential point of failure,and implementing multi-layered controls across your software stack,you can confidently pursue global expansion while drastically lowering your risk profile. Entivel Pty help businesses transition from being reactive to highly resilient.

Business Wire
Apr 8th, 2026
Trellix launches AI data security framework as breaches rise by $670K

Trellix has announced enhanced data security capabilities and a framework to help organisations adopt generative AI whilst protecting sensitive data. The solution addresses rising risks from shadow AI, which has contributed to data breach costs increasing by an average of $670,000. The platform combines Data Loss Prevention, Data Encryption and Database Security with a three-part framework establishing usage policies, governance and real-time visibility over AI tool interactions with sensitive data. Key features include an AI Data Risk Dashboard monitoring data loss to AI tools, Database Security with Analytics Hub protecting against unauthorised access, and Professional Services supporting policy development and technical implementation. Trellix has raised $295 million to date, helping security-conscious organisations manage AI adoption risks across cloud, on-premises and operational technology environments.

Business Wire
Feb 10th, 2026
Trellix SecondSight uses AI-driven threat hunting to detect low-noise advanced cyber attacks

Trellix has launched SecondSight, a threat hunting service designed to identify advanced threats that often evade automated detection systems. The service monitors low-noise signals that traditional defences miss, such as lateral movement indicators. SecondSight combines human expertise with AI-driven analytics across Trellix's endpoint, network and email security products. The service identifies subtle threat indicators that automated systems flag but cannot fully interpret, providing early warnings and actionable notifications to customers. The company released a threat hunting report highlighting five critical campaigns observed last year, including cases of OAuth abuse and spear-phishing operations. Trellix says the service addresses increased alert fatigue caused by threat actors' use of AI, acting as a force multiplier for security analysts monitoring sophisticated attacks.