Detection Engineer

Posted 3 Days Ago
Be an Early Applicant
Headquarters, AZ, USA
In-Office
Junior
Automotive
The Role
Build, tune, validate, and automate detection content across endpoint, identity, network, and cloud environments. Manage detections as code through Git, pull requests, CI/CD, and quality gates. Use Python and AI-assisted workflows to create tooling and analyze threats while critically reviewing AI output. Monitor detection health, map rules to MITRE ATT&CK, support attack simulations, document guidance, and collaborate with incident response teams.
Summary Generated by Built In

Copart, Inc. a technology leader and the premier online vehicle auction platform globally, with over 200 facilities located across the world, Copart links vehicle sellers to more than 750,000 buyers in over 190 countries.  We believe in providing an unmatched experience, every day and everywhere, driven by our people, processes, and technology. 

Copart is seeking a curious, engineering-minded Detection Engineer to join our global Security Operations team. You will build the detection content that identifies malicious activity across our endpoint, identity, network, and cloud estate — and prove that it works. Our detections are managed as code: version-controlled, peer-reviewed, and deployed through automation. Much of our authoring and threat-intelligence triage is AI-assisted, with agentic workflows drafting detection logic before an engineer reviews and ships it. We want someone genuinely fluent in working alongside these tools — able to move quickly with them, and clear-eyed about when not to trust them.


 Key Responsibilities:

 Detection Authoring & Tuning:

  • Design and author detection logic targeting adversary behaviors across endpoint, identity, network, and cloud telemetry, favoring durable behavioral indicators over brittle atomic ones.
  • Map content to MITRE ATT&CK and maintain complete rule metadata — owner, data sources, severity, lifecycle status.
  • Tune detections using real investigation outcomes, distinguishing logic that is wrong from logic that is right in a noisy environment and applying the correct fix for each.

Detection-as-Code & Automation:

  • Author detection content as code — rules, macros, lookups — in version control, using standard Git branching and pull request review.
  • Help extend the CI/CD pipeline that validates and deploys content, including schema checks, linting, and automated quality gates.
  • Write scripts and tooling (Python or similar) to automate repetitive work such as coverage reporting and data normalization, and partner with log source engineering to onboard new telemetry.

AI-Assisted Detection Engineering:

  • Work fluently within AI-assisted and agentic workflows where language models draft detection logic and perform first-pass triage and enrichment.
  • Critically review AI-generated content before it ships, taking full engineering ownership of the output regardless of how it was drafted.
  • Help build and refine the agent skills, prompts, and tool integrations the team relies on, and exercise judgment about where a human must stay in the loop.

Validation, Detection Health & Measurement:

  • Validate detection logic against historical telemetry and known-good and known-bad events before deployment, rather than relying on review alone.
  • Monitor deployed detections for silent failure — rules that have stopped firing, queries that error, logic broken by schema or environment drift — and treat a detection that never fires as a defect to investigate, not as evidence of a clean environment.
  • Contribute to attack simulation exercises and to program metrics covering coverage, alert fidelity, and detection health, converting every validated miss into detection work.

Collaboration & Communication:

  • Partner closely with Incident Response to shape alert context and response guidance, and to close the loop between what fires and what gets built next.
  • Create and maintain clear documentation — detection descriptions, triage guidance, runbooks, and lessons learned.
  • Communicate detection logic, coverage gaps, and technical risk clearly to technical and non-technical audiences alike, including colleagues who are not native English speakers, and escalate concerns early with recommendations attached.

Requirements & Preferences:

Required:

  • Demonstrable cybersecurity experience in detection engineering, security operations, threat hunting, incident response, or security automation.
  • Hands-on experience writing and tuning detection or search logic in a SIEM, EDR, or log analytics platform, and the ability to reason from an adversary technique to the telemetry that would reveal it.
  • Practical familiarity with AI-assisted engineering workflows, including LLM tooling used for authoring or analysis, and the judgment to verify and correct what those tools produce. This is a core expectation of the role, not a bonus.
  • Comfort with version control and pull request based collaboration, plus scripting ability in Python or a comparable language.
  • Exceptional written and verbal communication, with clarity and audience-appropriate messaging — this is a non-negotiable attribute. Strong analytical skills, attention to detail, and the intellectual honesty to say "I do not know yet, and here is how I will find out."

 

Preferred:

  • Approximately 2+ years in a dedicated cybersecurity engineering, detection, or security operations role, ideally with prior IT, infrastructure, or software engineering background.
  • Experience with detection-as-code — content in source control, peer-reviewed, deployed via CI/CD.
  • Experience with enterprise EDR and next-generation SIEM platforms, cloud security posture management, and vulnerability management tooling.
  • Experience building or extending AI agent tooling, custom skills, or tool-server integrations that connect language models to operational systems.
  • Familiarity with breach and attack simulation or adversary emulation tooling, commercial or open source, and comfort with APIs and structured data formats such as YAML and JSON.

Candidate Profile: The ideal candidate is a self-motivated engineer, genuinely curious about how adversaries operate and equally curious about how to prove a defense works. You are comfortable moving fast with AI-assisted tooling and equally comfortable being the person who catches when it is confidently wrong. You instinctively ask, "how would I know if this stopped working," and you would rather build the automation once than do the task fifty times. You will join a small team with strong engineering foundations and some real, openly acknowledged gaps — and meaningful ownership in closing them.



 

Benefits Summary:

· Medical/Dental/Vision

· 401k plus a company match

· ESPP - Employee Stock Purchase Plan

· EAP - Employee Assistance Program (no cost to you)

· Vacation & Sick pay

· Paid Company Holidays

· Life and AD&D Insurance

· Discounts

Along with many other employee benefits.


#LI-KK1

At Copart, we are focused on harnessing the power of diversity, inclusion, and collaboration. By embracing diverse perspectives, we open doors to innovation and unleash the full potential of our team. We are dedicated to fostering a workplace where everyone feels appreciated, included, and inspired to grow and contribute meaningfully.

E-Verify Program Participant: Copart participates in the Department of Homeland Security U.S. Citizenship and Immigration Services' E-Verify program (For U.S. applicants and employees only). Please click below to learn more about the E-Verify program:

  • E-verify Participation
  • Right to Work

Skills Required

  • Demonstrable cybersecurity experience in detection engineering, security operations, threat hunting, incident response, or security automation.
  • Hands-on experience writing and tuning detection or search logic in a SIEM, EDR, or log analytics platform.
  • Ability to reason from adversary techniques to the telemetry that would reveal them.
  • Practical familiarity with AI-assisted engineering workflows, including LLM tooling for authoring or analysis.
  • Ability to verify and correct AI-generated detection content.
  • Comfort with version control and pull request-based collaboration.
  • Scripting ability in Python or a comparable language.
  • Exceptional written and verbal communication skills.
  • Strong analytical skills, attention to detail, and intellectual honesty in identifying unknowns.
  • Approximately 2 or more years in a dedicated cybersecurity engineering, detection, or security operations role.
  • Prior IT, infrastructure, or software engineering background.
  • Experience with detection-as-code, source control, peer review, and CI/CD deployment.
  • Experience with enterprise EDR, next-generation SIEM, cloud security posture management, and vulnerability management tools.
  • Experience building or extending AI agent tooling, custom skills, or tool-server integrations.
  • Familiarity with breach and attack simulation or adversary emulation tooling.
  • Comfort with APIs and structured data formats such as YAML and JSON.
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Dallas, TX
5,001 Employees
Year Founded: 1982

What We Do

Copart, a global online auto auction company headquartered in Dallas, Texas is a top-performing S&P 500 company, as noted by The Wall Street Journal. Copart is a global technology leader in the online vehicle auction industry that connects its buyers and sellers via its patented cutting-edge VB3 technology. With a passion for excellence, Copart has a great company culture and strong dedication to our employees. Founded in 1982, Copart connects more than 750,000 buyers and sellers from over 200 locations around the world. With our innovative technology, we remarket salvage and clean title vehicles to dealers, dismantlers, rebuilders, exporters and end users through a multi-channel online internet platform. Copart’s diverse and extensive inventory features more than 175,000 vehicles available online every day, including early and late-model cars, classics, trucks, SUVs, motorcycles, boats, jet-skis, snowmobiles and RVs. Copart sells vehicles on behalf of insurance companies, banks, finance companies, fleet owners, car dealerships, cars sourced from the general public and others. Because we are a 100% online auto auction company, Copart Members can browse our incredible inventory, set their own price and get great deals on vehicles through their home computer, smartphone or other mobile device. Copart’s vehicles can range in condition from damaged vehicles that can be used as rebuild projects to like-new, used vehicles. Copart is the parent company to a portfolio of auto service companies, including CashForCars.com, CrashedToys, and National Powersport Auctions (NPA). We currently operate in the United States (Copart.com), Canada (Copart.ca), the United Kingdom (Copart.co.uk), the Republic of Ireland (Copart.ie), Brazil (Copart.com.br), Germany (Copart.de), the United Arab Emirates, Oman and Bahrain (Copartmea.com), Spain (Copart.es), and Finland (copart.fi).

Similar Jobs

Remote or Hybrid
US
15100 Employees
137K-191K Annually

Liberty Mutual Insurance Logo Liberty Mutual Insurance

Inside Sales Representative

Artificial Intelligence • Fintech • Insurance • Marketing Tech • Software • Analytics
Remote or Hybrid
12 Locations
40000 Employees
45K-85K Annually

Chewy Logo Chewy

Pharmacy Technician

eCommerce • Healthtech • Pet • Retail • Pharmaceutical
Hybrid
Goodyear, AZ, USA
17800 Employees
21-21 Hourly

Optum Logo Optum

Associate Patient Care Coordinator

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
In-Office
Scottsdale, AZ, USA
160000 Employees
16-29 Hourly

Similar Companies Hiring

UL Solutions Thumbnail
Automotive • Professional Services • Software • Consulting • Energy • Chemical • Renewable Energy
Chicago, IL
15000 Employees
HERE Technologies Thumbnail
Artificial Intelligence • Automotive • Computer Vision • Information Technology • Internet of Things • Logistics • Software
Amsterdam, NL
6000 Employees
Vega Thumbnail
Artificial Intelligence • Automotive • Insurance • Transportation
US
43 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account