Enter a job title or keyword

Detection Engineer

Copart


Job Location:

Dallas, IA - USA

Monthly Salary: Not provided by the employer
Posted: 29 September 2026 (14 hours ago)
Application Deadline: 27 December 2026
Vacancies: 1 Vacancy

Job Summary

Copart Inc. a technology leader and the premier online vehicle auction platform globally with over 200 facilities located across the world Copart links vehicle sellers to more than 750000 buyers in over 190 countries. We believe in providing an unmatched experience every day and everywhere driven by our people processes and technology.

Copart is seeking a curious engineering-minded Detection Engineer to join our global Security Operations team. You will build the detection content that identifies malicious activity across our endpoint identity network and cloud estate and prove that it works. Our detections are managed as code: version-controlled peer-reviewed and deployed through automation. Much of our authoring and threat-intelligence triage is AI-assisted with agentic workflows drafting detection logic before an engineer reviews and ships it. We want someone genuinely fluent in working alongside these tools able to move quickly with them and clear-eyed about when not to trust them.


Key Responsibilities:

Detection Authoring & Tuning:

  • Design and author detection logic targeting adversary behaviors across endpoint identity network and cloud telemetry favoring durable behavioral indicators over brittle atomic ones.
  • Map content to MITRE ATT&CK and maintain complete rule metadata owner data sources severity lifecycle status.
  • Tune detections using real investigation outcomes distinguishing logic that is wrong from logic that is right in a noisy environment and applying the correct fix for each.

Detection-as-Code & Automation:

  • Author detection content as code rules macros lookups in version control using standard Git branching and pull request review.
  • Help extend the CI/CD pipeline that validates and deploys content including schema checks linting and automated quality gates.
  • Write scripts and tooling (Python or similar) to automate repetitive work such as coverage reporting and data normalization and partner with log source engineering to onboard new telemetry.

AI-Assisted Detection Engineering:

  • Work fluently within AI-assisted and agentic workflows where language models draft detection logic and perform first-pass triage and enrichment.
  • Critically review AI-generated content before it ships taking full engineering ownership of the output regardless of how it was drafted.
  • Help build and refine the agent skills prompts and tool integrations the team relies on and exercise judgment about where a human must stay in the loop.

Validation Detection Health & Measurement:

  • Validate detection logic against historical telemetry and known-good and known-bad events before deployment rather than relying on review alone.
  • Monitor deployed detections for silent failure rules that have stopped firing queries that error logic broken by schema or environment drift and treat a detection that never fires as a defect to investigate not as evidence of a clean environment.
  • Contribute to attack simulation exercises and to program metrics covering coverage alert fidelity and detection health converting every validated miss into detection work.

Collaboration & Communication:

  • Partner closely with Incident Response to shape alert context and response guidance and to close the loop between what fires and what gets built next.
  • Create and maintain clear documentation detection descriptions triage guidance runbooks and lessons learned.
  • Communicate detection logic coverage gaps and technical risk clearly to technical and non-technical audiences alike including colleagues who are not native English speakers and escalate concerns early with recommendations attached.

Requirements & Preferences:

Required:

  • Demonstrable cybersecurity experience in detection engineering security operations threat hunting incident response or security automation.
  • Hands-on experience writing and tuning detection or search logic in a SIEM EDR or log analytics platform and the ability to reason from an adversary technique to the telemetry that would reveal it.
  • Practical familiarity with AI-assisted engineering workflows including LLM tooling used for authoring or analysis and the judgment to verify and correct what those tools produce. This is a core expectation of the role not a bonus.
  • Comfort with version control and pull request based collaboration plus scripting ability in Python or a comparable language.
  • Exceptional written and verbal communication with clarity and audience-appropriate messaging this is a non-negotiable attribute. Strong analytical skills attention to detail and the intellectual honesty to say I do not know yet and here is how I will find out.

Preferred:

  • Approximately 2 years in a dedicated cybersecurity engineering detection or security operations role ideally with prior IT infrastructure or software engineering background.
  • Experience with detection-as-code content in source control peer-reviewed deployed via CI/CD.
  • Experience with enterprise EDR and next-generation SIEM platforms cloud security posture management and vulnerability management tooling.
  • Experience building or extending AI agent tooling custom skills or tool-server integrations that connect language models to operational systems.
  • Familiarity with breach and attack simulation or adversary emulation tooling commercial or open source and comfort with APIs and structured data formats such as YAML and JSON.

Candidate Profile: The ideal candidate is a self-motivated engineer genuinely curious about how adversaries operate and equally curious about how to prove a defense works. You are comfortable moving fast with AI-assisted tooling and equally comfortable being the person who catches when it is confidently wrong. You instinctively ask how would I know if this stopped working and you would rather build the automation once than do the task fifty times. You will join a small team with strong engineering foundations and some real openly acknowledged gaps and meaningful ownership in closing them.




Benefits Summary:

Medical/Dental/Vision

401k plus a company match

ESPP - Employee Stock Purchase Plan

EAP - Employee Assistance Program (no cost to you)

Vacation & Sick pay

Paid Company Holidays

Life and AD&D Insurance

Discounts

Along with many other employee benefits.


#LI-KK1

At Copart we are focused on harnessing the power of diversity inclusion and collaboration. By embracing diverse perspectives we open doors to innovation and unleash the full potential of our team. We are dedicated to fostering a workplace where everyone feels appreciated included and inspired to grow and contribute meaningfully.

E-Verify Program Participant: Copart participates in the Department of Homeland Security U.S. Citizenship and Immigration Services E-Verify program (For U.S. applicants and employees only). Please click below to learn more about the E-Verify program:


Required Experience:

IC


About Company

Register to start bidding & winning! Global leader in 100% online auto auctions. 175,000+ total loss salvage, used, wholesale and repairable cars, trucks, SUVs, motorcycles, and more available for sale.

View Profile View Profile