Copart
Vulnerability Management Engineering Intern
Dallas, TX - Headquarters
Get past the screening software and onto a recruiter's desk
hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.
- Keywords matched to this posting
- Fit score before you apply
- Cover letter included
Matched against 2.3M live jobs from 200,000+ employers in 200+ countries.
Tailor my resume for this job →hirly's read of this role
- Seniority
- Internship
- Country
- US
- Work mode
- On-site / unstated
- First seen by hirly
- 29 Sept 2026
Derived automatically from the posting. Upload your resume above to see how the role scores against it.
the posting
Copart, Inc. a technology leader and the premier online vehicle auction platform globally, with over 200 facilities located across the world, Copart links vehicle sellers to more than 750,000 buyers in over 190 countries. We believe in providing an unmatched experience, every day and everywhere, driven by our people, processes, and technology.
- Job Summary:
- Copart is seeking an engineering-minded Vulnerability Management Engineer to join our global Security Operations team. This role goes well beyond running scans and passing findings along. We are building toward a continuous exposure management program, where every finding arrives ranked by real exploitability and by the controls we already have, and routed to the team that can fix it. You will build the data pipelines, the prioritization logic, the automation that moves work to the right owner, and the validation that proves our controls do what we claim. Much of this work is AI-assisted, with agentic workflows performing analysis and enrichment before an engineer reviews the result. We want someone genuinely fluent with those tools — able to move quickly with them, and clear-eyed about when not to trust them.
Key Responsibilities:
Exposure Discovery & Security Data Engineering:
Operate and tune the scanning and assessment platforms covering infrastructure, endpoints, and cloud, and close gaps in asset coverage rather than assuming the inventory is complete.
Build and maintain the pipelines that export, normalize, and store findings, reconciling asset identity and tagging across sources so that one host is not three records.
Query and manipulate large security datasets to answer posture questions, and expand what they cover beyond CVEs toward misconfigurations, identity exposure, and other risk traditional scanning misses.
Risk Prioritization & Contextual Analysis:
Develop and refine the scoring logic that turns raw findings into a ranked, defensible work queue — exploitability, known exploited vulnerability status, threat intelligence, asset criticality, and exposure.
Apply credit for compensating controls already deployed, and stay rigorous about the difference between a control that is merely present and one that genuinely interrupts the exploitation path.
Assess whether a vulnerability is genuinely applicable and impactful in Copart's environment, and be comfortable reporting "this one does not matter here, and here is why."
AI-Assisted Workflows & Automation:
Work fluently within AI-assisted and agentic workflows where language models perform enrichment, control assessment, and first-pass analysis at a scale no human could review by hand.
Critically review AI-generated analysis before it influences a score, a report, or a remediation decision, taking full ownership of the output regardless of how it was produced.
Build and maintain backend automation in Python or similar, with REST and GraphQL APIs and middleware, connecting security tooling to internal databases and platforms — including the agent skills and integrations the team relies on.
Remediation Mobilization & Validation:
Partner with Infrastructure teams (Network, Systems, DevOps, Endpoint Engineering) to embed patching and remediation into their existing workflows, so fixes are routed and tracked rather than chased.
Group findings into the smallest set of remediation actions that eliminate the most exposure, and report on what each action is actually worth.
Validate that remediation and compensating controls work as claimed — that fixes landed, that control coverage is evidenced rather than assumed, and that reported posture reflects reality.
Communication, Documentation & Assurance:
Communicate vulnerability risk, remediation priorities, and posture trends clearly to technical and non-technical audiences alike, including colleagues who are not native English speakers, and deliver time-sensitive updates to large groups with confidence.
Create and maintain documentation — processes, procedures, runbooks, lessons learned — and apply frameworks such as NIST and CIS to hardening and compliance automation.
Support audit and evidence requests, participate in tabletop exercises and After Action Reviews, and escalate concerns early with recommendations attached.
Requirements & Preferences:
Required:
Demonstrable cybersecurity experience in vulnerability management, infrastructure or cloud security engineering, security operations, or security automation.
Solid grasp of IT infrastructure fundamentals — operating systems, networking, DNS, system administration, cloud services, APIs — and the ability to reason about how a vulnerability is actually exploited.
Hands-on scripting and automation ability in Python or a comparable language, with a working understanding of database structures (SQL or NoSQL) and data manipulation.
Practical familiarity with AI-assisted engineering workflows, including LLM tooling used for analysis or automation, and the judgment to verify and correct what those tools produce. This is a core expectation of the role, not a bonus.
Proven ability to judge a vulnerability's real applicability and impact in a large, dynamic enterprise rather than deferring to a vendor severity rating.
Exceptional written and verbal communication, with clarity and audience-appropriate messaging — this is a non-negotiable attribute. Strong analytical skills, attention to detail, and the intellectual honesty to say "I do not know yet, and here is how I will find out."
Preferred:
Approximately 2+ years in IT infrastructure (network, systems, or security administration) plus time in a dedicated cybersecurity engineering or operations role.
Experience operating enterprise vulnerability scanning platforms, cloud security posture management tooling, and endpoint detection and response platforms.
Experience with API architectures and middleware (REST, GraphQL, FastAPI), version control and pull request collaboration, and configuration management tooling such as Ansible.
Experience building or extending AI agent tooling, custom skills, or tool-server integrations that connect language models to operational systems.
Exposure to continuous threat exposure management, attack surface management, or breach and attack simulation tooling, and familiarity with exploitability intelligence such as KEV and EPSS. Subject matter depth in infrastructure and cloud vulnerabilities, as distinct from application-layer, and experience on a globally distributed team.
Candidate Profile: The ideal candidate is a self-motivated engineer who is as interested in why a finding matters as in whether it exists. You are comfortable moving fast with AI-assisted tooling and equally comfortable being the person who catches when it is confidently wrong. You are skeptical of numbers you cannot trace, you would rather build the automation once than do the task fifty times, and you understand that the hardest part of vulnerability management is not finding things — it is getting them fixed and proving they stayed fixed. You communicate well with infrastructure engineers, leaders, and your own team alike, and you are comfortable voicing a dissenting view and then helping solve the problem you raised. You will join a small team with strong data and scoring foundations and some real, openly acknowledged gaps — and meaningful ownership in closing them.
Benefits Summary:
· Medical
#LI-KK1


 At Copart, we are focused on harnessing the power of diversity, inclusion, and collaboration. By embracing diverse perspectives, we open doors to innovation and unleash the full potential of our team. We are dedicated to fostering a workplace where everyone feels appreciated, included, and inspired to grow and contribute meaningfully.
E-Verify Program Participant: Copart participates in the Department of Homeland Security U.S. Citizenship and Immigration Services' E-Verify program (
Similar jobs
- Manufacturing Engineering Intern - Summer 2027Ralliant · Plainville, CT, United StatesFirst seen today
- Manufacturing Engineering Intern - Summer 2027Ralliant · Boxborough, MA, United StatesFirst seen today
- Engineering InternThe Redpath Group · Patagonia, AZ, United StatesFirst seen today
- Structural Engineering Intern/Co-op – Infrastructure (Summer 2027)Stantec · New Haven, CT, United States; Hartford, CT, United StatesFirst seen today
- Process Engineering Intern/Co-op - Buildings (Summer 2027)Stantec · Burlington, MA, United States; Philadelphia, PA, United StatesFirst seen today
Browse similar roles
Want this one?
Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.
Tailor my resume for this job