Live opening · Posted 1 day ago

Vulnerability Management Engineering Intern 

Copart Catastrophe Response Fleet, LLC · Dallas, TX - Headquarters
Workday
You are 1 day behind. JobBeeper subscribers saw this role while it was still new.

At a glance

The key details from the original listing.

Posted 1 day ago
CompanyCopart Catastrophe Response Fleet, LLC
LocationDallas, TX - Headquarters
SkillsPython, GraphQL
SourceWorkday
Listed1 day ago

Your early-applicant advantage

Live timing from JobBeeper.

Live data
32 min from Workday publishing this role to us finding it
12 min median time from a role going live to a subscriber being told
6 hours subscribers had this role before this page existed
71,069 roles found in the last 24 hours — the newest are not on this site yet
Start your free trial →

About the role

Description supplied by the original job listing.

Copart, Inc. a technology leader and the premier online vehicle auction platform globally, with over 200 facilities located across the world, Copart links vehicle sellers to more than 750,000 buyers in over 190 countries. We believe in providing an unmatched experience, every day and everywhere, driven by our people, processes, and technology.
Job Summary:
Copart is seeking an engineering-minded Vulnerability Management Engineer to join our global Security Operations team. This role goes well beyond running scans and passing findings along. We are building toward a continuous exposure management program, where every finding arrives ranked by real exploitability and by the controls we already have, and routed to the team that can fix it. You will build the data pipelines, the prioritization logic, the automation that moves work to the right owner, and the validation that proves our controls do what we claim. Much of this work is AI-assisted, with agentic workflows performing analysis and enrichment before an engineer reviews the result. We want someone genuinely fluent with those tools — able to move quickly with them, and clear-eyed about when not to trust them.
Key Responsibilities:
Exposure Discovery & Security Data Engineering:
Operate and tune the scanning and assessment platforms covering infrastructure, endpoints, and cloud, and close gaps in asset coverage rather than assuming the inventory is complete.
Build and maintain the pipelines that export, normalize, and store findings, reconciling asset identity and tagging across sources so that one host is not three records.
Query and manipulate large security datasets to answer posture questions, and expand what they cover beyond CVEs toward misconfigurations, identity exposure, and other risk traditional scanning misses.
Risk Prioritization & Contextual Analysis:
Develop and refine the scoring logic that turns raw findings into a ranked, defensible work queue — exploitability, known exploited vulnerability status, threat intelligence, asset criticality, and exposure.
Apply credit for compensating controls already deployed, and stay rigorous about the difference between a control that is merely present and one that genuinely interrupts the exploitation path.
Assess whether a vulnerability is genuinely applicable and impactful in Copart's environment, and be comfortable reporting "this one does not matter here, and here is why."
AI-Assisted Workflows & Automation:
Work fluently within AI-assisted and agentic workflows where language models perform enrichment, control assessment, and first-pass analysis at a scale no human could review by hand.
Critically review AI-generated analysis before it influences a score, a report, or a remediation decision, taking full ownership of the output regardless of how it was produced.
Build and maintain backend automation in Python or similar, with REST and GraphQL APIs and middleware, connecting security tooling to internal databases and platforms — including the agent skills and integrations the team relies on.
Remediation Mobilization & Validation:
Partner with Infrastructure teams (Network, Systems, DevOps, Endpoint Engineering) to embed patching and remediation into their existing workflows, so fixes are routed and tracked rather than chased.
Group findings into the smallest set of remediation actions that eliminate the most exposure, and report on what each action is actually worth.
Validate that remediation and compensating controls work as claimed — that fixes landed, that control coverage is evidenced rather than assumed, and that reported posture reflects reality.
Communication, Documentation & Assurance:
Communicate vulnerability risk, remediation priorities, and posture trends clearly to technical and non-technical audiences alike, including colleagues who are not native English speakers, and deliver time-sensitive updates to large groups with confidence.
Create and maintain documentation — processes, procedures, runbooks, lessons learned — and apply frameworks such as NIST and CIS to hardening and compliance automation.
Support audit and evidence requests, participate in tabletop exercises and After Action Reviews, and escalate concerns early with recommendations attached.
Requirements & Preferences:
Required:
Demonstrable cybersecurity experience in vulnerability management, infrastructure or cloud security engineering, security operations, or security automation.
Solid grasp of IT infrastructure fundamentals — operating systems, networking, DNS, system administration, cloud services, APIs — and the ability to reason about how a vulnerability is actually exploited.
Hands-on scripting and automation ability in Python or a comparable language, with a working understanding of database structures (SQL or NoSQL) and data manipulation.
Practical familiarity with AI-assisted engineering workflows, including LLM tooling used for analysis or automation, and the judgment to verify and correct what those tools produce. This is a core expectation of the role, not a bonus.
Proven ability to judge a vulnerability's real applicability and impact in a large, dynamic enterprise rather than deferring to a vendor severity rating.
Exceptional written and verbal communication, with clarity and audience-appropriate messaging — this is a non-negotiable attribute. Strong analytical skills, attention to detail, and the intellectual honesty to say "I do not know yet, and here is how I will find out."
Preferred:
Approximately 2+ years in IT infrastructure (network, systems, or security administration) plus time in a dedicated cybersecurity engineering or operations role.
Experience operating enterprise vulnerability scanning platforms, cloud security posture management tooling, and endpoint detection and response platforms.
Experience with API architectures and middleware (REST, GraphQL, FastAPI), version control and pull request collaboration, and configuration management tooling such as Ansible.
Experience building or extending AI agent tooling, custom skills, or tool-server integrations that connect language models to operational systems.
Exposure to continuous threat exposure management, attack surface management, or breach and attack simulation tooling, and familiarity with exploitability intelligence such as KEV and EPSS. Subject matter depth in infrastructure and cloud vulnerabilities, as distinct from application-layer, and experience on a globally distributed team.
Candidate Profile: The ideal candidate is a self-motivated engineer who is as interested in why a finding matters as in whether it exists. You are comfortable moving fast with AI-assisted tooling and equally comfortable being the person who catches when it is confidently wrong. You are skeptical of numbers you cannot trace, you would rather build the automation once than do the task fifty times, and you understand that the hardest part of vulnerability management is not finding things — it is getting them fixed and proving they stayed fixed. You communicate well with infrastructure engineers, leaders, and your own team alike, and you are comfortable voicing a dissenting view and then helping solve the problem you raised. You will join a small team with strong data and scoring foundations and some real, ope

Get JobBeeper Mobile App

Never miss a job opening! Get instant job alerts on your phone.

Subscribers see fresh openings within minutes. Download the JobBeeper App on Google Play to get real-time push notifications and apply before anyone else.

⚡ Instant Push Alerts 🎯 Tailored Filters 🚀 Direct Employer Links
GET IT ON Google Play

More openings worth a look

Recently tracked roles with full details and direct application links.

6 roles
Good roles move before most people even see them. Tell JobBeeper what you want and get fresh matches delivered in minutes.
Start your free trial →
⚡ Get fresh job alerts 📱 Get App