Copart is seeking a curious, engineering-minded Detection Engineer to join our global Security Operations team. You will build the detection content that identifies malicious activity across our endpoint, identity, network, and cloud estate - and prove that it works. Our detections are managed as code: version-controlled, peer-reviewed, and deployed through automation. Much of our authoring and threat-intelligence triage is AI-assisted, with agentic workflows drafting detection logic before an engineer reviews and ships it. We want someone genuinely fluent in working alongside these tools - able to move quickly with them, and clear-eyed about when not to trust them.
Key Responsibilities: Detection Authoring & Tuning:
- Design and author detection logic targeting adversary behaviors across endpoint, identity, network, and cloud telemetry, favoring durable behavioral indicators over brittle atomic ones.
- Map content to MITRE ATT&CK and maintain complete rule metadata - owner, data sources, severity, lifecycle status.
- Tune detections using real investigation outcomes, distinguishing logic that is wrong from logic that is right in a noisy environment and applying the correct fix for each.
Detection-as-Code & Automation:
- Author detection content as code - rules, macros, lookups - in version control, using standard Git branching and pull request review.
- Help extend the CI/CD pipeline that validates and deploys content, including schema checks, linting, and automated quality gates.
- Write scripts and tooling (Python or similar) to automate repetitive work such as coverage reporting and data normalization, and partner with log source engineering to onboard new telemetry.
AI-Assisted Detection Engineering:
- Work fluently within AI-assisted and agentic workflows where language models draft detection logic and perform first-pass triage and enrichment.
- Critically review AI-generated content before it ships, taking full engineering ownership of the output regardless of how it was drafted.
- Help build and refine the agent skills, prompts, and tool integrations the team relies on, and exercise judgment about where a human must stay in the loop.
Validation, Detection Health & Measurement:
- Validate detection logic against historical telemetry and known-good and known-bad events before deployment, rather than relying on review alone.
- Monitor deployed detections for silent failure - rules that have stopped firing, queries that error, logic broken by schema or environment drift - and treat a detection that never fires as a defect to investigate, not as evidence of a clean environment.
- Contribute to attack simulation exercises and to program metrics covering coverage, alert fidelity, and detection health, converting every validated miss into detection work.
Collaboration & Communication:
- Partner closely with Incident Response to shape alert context and response guidance, and to close the loop between what fires and what gets built next.
- Create and maintain clear documentation - detection descriptions, triage guidance, runbooks, and lessons learned.
- Communicate detection logic, coverage gaps, and technical risk clearly to technical and non-technical audiences alike, including colleagues who are not native English speakers, and escalate concerns early with recommendations attached.
Requirements & Preferences:Required:
- Demonstrable cybersecurity experience in detection engineering, security operations, threat hunting, incident response, or security automation.
- Hands-on experience writing and tuning detection or search logic in a SIEM, EDR, or log analytics platform, and the ability to reason from an adversary technique to the telemetry that would reveal it.
- Practical familiarity with AI-assisted engineering workflows, including LLM tooling used for authoring or analysis, and the judgment to verify and correct what those tools produce. This is a core expectation of the role, not a bonus.
- Comfort with version control and pull request based collaboration, plus scripting ability in Python or a comparable language.
- Exceptional written and verbal communication, with clarity and audience-appropriate messaging - this is a non-negotiable attribute. Strong analytical skills, attention to detail, and the intellectual honesty to say "I do not know yet, and here is how I will find out."
Preferred:
- Approximately 2+ years in a dedicated cybersecurity engineering, detection, or security operations role, ideally with prior IT, infrastructure, or software engineering background.
- Experience with detection-as-code - content in source control, peer-reviewed, deployed via CI/CD.
- Experience with enterprise EDR and next-generation SIEM platforms, cloud security posture management, and vulnerability management tooling.
- Experience building or extending AI agent tooling, custom skills, or tool-server integrations that connect language models to operational systems.
- Familiarity with breach and attack simulation or adversary emulation tooling, commercial or open source, and comfort with APIs and structured data formats such as YAML and JSON.
Candidate Profile: The ideal candidate is a self-motivated engineer, genuinely curious about how adversaries operate and equally curious about how to prove a defense works. You are comfortable moving fast with AI-assisted tooling and equally comfortable being the person who catches when it is confidently wrong. You instinctively ask, "how would I know if this stopped working," and you would rather build the automation once than do the task fifty times. You will join a small team with strong engineering foundations and some real, openly acknowledged gaps - and meaningful ownership in closing them.
Benefits Summary:• Medical/Dental/Vision
• 401k plus a company match
• ESPP - Employee Stock Purchase Plan
• EAP - Employee Assistance Program (no cost to you)
• Vacation & Sick pay
• Paid Company Holidays
• Life and AD&D Insurance
• Discounts
Along with many other employee benefits.
#LI-KK1