1 to 25 of 125 Kusto Query Language Jobs

Tier 2 SOC Analyst- Cyber Threat Analysis Center

Location
South Kesteven, England, United Kingdom
Tier 1 Analysts, determining threat severity and advising on initial response actions. Apply expertise in SIEM solutions utilizing Kusto Query Language (KQL), to perform log analysis, event correlation, and thorough documentation of security incidents. Identify and escalate critical threats to Tier 3 Analysts with detailed analysis … analysis; some exposure to additional analysis tools such as basic XDR platforms. Able to demonstrate proficient knowledge using Kusto Query Language (KQL) to search and filter logs effectively. Familiar with open-source intelligence (OSINT) techniques to aid in identifying potential threats and gathering information. Able to communicate ...

Security Content Engineer

Location
Greater London, England, United Kingdom
expertise in a fast-paced, collaborative environment. What You'll Do: Own and Enhance Detection Content:Autonomously develop, test, andmaintainhigh-fidelity detection logic in KQL for the Microsoft Sentinel environment. You will own a portfolio of content, ensuring its long-term effectiveness and performance. Conduct Advanced Tuning & Optimization:Perform independent … creation. Deep, hands-onexpertisewith the Microsoft security stack, including Microsoft Sentinel, Microsoft 365 Defender, and Logic Apps. Highproficiencyin Kusto Query Language (KQL), with proven experience writing complex, optimized queries for detection and hunting. Strong,demonstratedexperience automating security workflowsusing SOAR platforms, APIs, or scripting languages (Python, PowerShell). ...

Security Content Engineer

Hiring Organisation
BlueVoyant
Location
United Kingdom
Salary
£ 70 K
fast-paced, collaborative environment.What You'll Do:Own and Enhance Detection Content: Autonomously develop, test, and maintain high-fidelity detection logic in KQL for the Microsoft Sentinel environment. You will own a portfolio of content, ensuring its long-term effectiveness and performance. Conduct Advanced Tuning & Optimization: Perform independent and complex … expertise with the Microsoft security stack, including Microsoft Sentinel, Microsoft 365 Defender, and Logic Apps. High proficiency in Kusto Query Language (KQL), with proven experience writing complex, optimized queries for detection and hunting. Strong, demonstrated experience automating security workflows using SOAR platforms, APIs, or scripting languages (Python ...

Exchange SME

Hiring Organisation
Morson Edge
Location
London, United Kingdom
Employment Type
Contract
Contract Rate
£400 - 440 per day
Implement security best practices, including privileged access management and least privilege. Microsoft Sentinel Deploy, configure, and manage Microsoft Sentinel. Develop and maintain analytics rules, KQL queries, workbooks, and automation. Investigate security incidents and suspicious activity. Integrate Microsoft Sentinel with Active Directory, Microsoft 365, Defender, and other security platforms. Develop Logic … Services Group Policy DNS, DHCP, TCP/IP PowerShell Microsoft 365 Microsoft Entra ID Microsoft Defender Microsoft Sentinel Kusto Query Language (KQL) Windows Server Azure Hybrid identity and Exchange environments Security monitoring and incident response Please send your CV fo immediate interview ...

Managing Engineer - Observability, Pipeline & Analytics (Hybrid)

Location
Belfast City District, Northern Ireland, United Kingdom
transformation initiatives. Desirable Skills: Experience implementing telemetry cost optimization and data reduction strategies at enterprise scale. Knowledge of Kusto Query Language (KQL) and large‐scale analytics platforms. Experience with Cribl, ADX, Datadog Pipelines, Splunk, Sentinel, Kafka, Event Hubs, Open Telemetry, Elastic, Grafana, or similar observability ecosystems. Ability ...

Managing Engineer - Observability, Pipeline & Analytics (Hybrid)

Location
Belfast City District, Northern Ireland, United Kingdom
transformation initiatives. Desirable Skills: Experience implementing telemetry cost optimization and data reduction strategies at enterprise scale. Knowledge of Kusto Query Language (KQL) and large-scale analytics platforms. Experience with Cribl, ADX, Datadog Pipelines, Splunk, Sentinel, Kafka, Event Hubs, Open Telemetry, Elastic, Grafana, or similar observability ecosystems. Ability ...

Senior Lead Security Operations Analyst

Hiring Organisation
Companies House
Location
Cowbridge, South Glamorgan, United Kingdom
Salary
£ 60 K
security incidents. Experience developing and improving Security Operations capabilities, including monitoring processes, incident response procedures, playbooks and automation. Advanced knowledge of Microsoft Sentinel, including Kusto Query Language, analytics rules, security investigations, log analysis and automation. Strong knowledge of Amazon Web Services security, including cloud logging, identity ...

Senior Cyber Threat Intelligence (CTI) Analyst

Location
United Kingdom
attacker tooling using sandbox or detonation environments and extracting IOCs, C2 infrastructure, and behavioral indicators.Proficiency in at least one query language (KQL, SPL, CQL, SQL), the ability to read and understand code, and working scripting ability (e.g., Python, Bash) for enrichment and automation.Strong written and verbal communication skills ...

Senior Cyber Threat Intelligence (CTI) Analyst

Location
Greater London, England, United Kingdom
attacker tooling using sandbox or detonation environments and extracting IOCs, C2 infrastructure, and behavioural indicators. Proficiency in at least one query language (KQL, SPL, CQL, SQL), the ability to read and understand code, and working scripting ability (e.g., Python, Bash) for enrichment and automation. Strong written and verbal ...

Automation Engineer

Hiring Organisation
Sopra Steria
Location
Farnborough, Hampshire, United Kingdom
Employment Type
Full-Time
Salary
£55,000 - £60,000 per annum
cloud-based engineering principles. It would be great if you had: Experience in Cyber Security, SOC or Security Engineering environments. Microsoft Sentinel experience. KQL, SQL or other query language knowledge. Power BI data modelling, DAX and Power Query experience. Logic Apps, Power Automate or Azure Automation. Terraform ...

SecOps Platform Engineer

Location
United Kingdom
Microsoft Intune, Jamf Suite, Conditional Access, DLP, MFA, and compliance policies, including SOC2 and ISO27001. Previously used scripting tools such as PowerShell, Python, Bash, KQL, or SQL. You\'ll stand out from the crowd if you also have Certifications such as AZ-500, SC-200, CISSP, CISM, SSCP, or CCSP. ...

Senior Cyber Security Analyst

Hiring Organisation
Lightsource bp
Location
London, United Kingdom
Salary
£ 80 K
Security Operations Center (SOC) or incident response role Advanced proficiency with Microsoft Defender XDR and expert-level knowledge of Microsoft Sentinel, including KQL query writing and analytics rule development Strong hands-on experience with Microsoft Defender for Endpoint, including policy configuration and threat investigation Demonstrable experience responding to cyber ...

Threat Intelligence Analyst

Location
Greater London, England, United Kingdom
sharing platforms, and dark web monitoring tools Correlate external intelligence with internal security events using Microsoft Sentinel and Microsoft Defender Develop and maintain advanced KQL queries for threat hunting, detection engineering, and incident investigation Produce actionable threat intelligence reports, threat actor profiles, IoCs, and executive briefings Support and participate … methodologies, and intelligence frameworks such as MITRE ATT&CK, the Diamond Model, and Cyber Kill Chain Advanced knowledge of Microsoft Sentinel, Microsoft Defender, and KQL for threat hunting and investigation Experience working with threat intelligence platforms and dark web monitoring solutions, such as DarkIQ or equivalent Strong analytical skills with ...

SOAR Engineer

Location
Warwick, England, United Kingdom
refinement. Conduct in-depth analysis of the existing functionality of the CSIRT, propose and enact improvements to the service. About you: Strong proficiency in KQL and detection engineering. Have a high level of ability to create and develop security orchestration and automated response (SOAR). Experience and working knowledge with ...

Level 3 SOC Analyst

Location
Belfast City District, Northern Ireland, United Kingdom
platforms, including IBM QRadar, Microsoft Sentinel and LogRhythm In-depth experience with Microsoft Sentinel, including use case and rule development, workbook/playbook creation, KQL & Logic Apps/SOAR Experience in managing Microsoft Sentinel as an MSSP, including Lighthouse, and management and multi-customer environments using DevOps How this aligns ...

Level 3 SOC Analyst

Hiring Organisation
Capita
Location
Belfast, Down, United Kingdom
Salary
£ 60 K
SIEM platforms, including IBM QRadar, Microsoft Sentinel and LogRhythmIn-depth experience with Microsoft Sentinel, including use case and rule development, workbook/playbook creation, KQL & Logic Apps/SOAR Experience in managing Microsoft Sentinel as an MSSP, including Lighthouse, and management and multi-customer environments using DevOps How this aligns ...

Technical Analyst

Location
United Kingdom
cataloguing and lineage use cases. Skills & Competencies Ability to configure and manage Purview policies and scanning tools. Strong analytical and troubleshooting skills. Familiarity with KQL, PowerShell, or Microsoft Graph. Ability to interpret logs, alerts, and governance reporting. Strong documentation and verbal communication skills. Ability to work collaboratively with cross functional ...

Lead Platform Operations Engineer

Location
Greater London, England, United Kingdom
Networking, Security, Data) Strong hands-on experience with Kubernetes, Docker, and container orchestration Expertise in Infrastructure as Code (Terraform) and scripting (PowerShell, Bash, SQL, KQL) Proven delivery of CI/CD pipelines (Azure DevOps YAML essential) Experience implementing security tooling (SAST, DAST, container scanning, WAF) Strong knowledge of cloud security ...

Manager - Cyber Security Specialist

Location
West of England, England, United Kingdom
government). Knowledge of secure system integration and API security. Strong working knowledge of SOC processes and SIEM engineering, preferably using Microsoft Sentinel (KQL, analytics rule tuning, workbooks, automation) and Microsoft Defender security tools. Understanding of supply chain security risks. SC clearance. QUALIFICATIONS & CERTIFICATIONS Degree in Cyber Security ...

Cyber Security Engineer

Location
Aberdeen City, Scotland, United Kingdom
Defender across endpoint, identity, Office 365, and cloud apps, including triage and tuning of Defender alerts. Microsoft Sentinel, including writing and tuning your own KQL queries, analytic rules, and workbooks. Microsoft Entra ID and Conditional Access policy design, testing, and troubleshooting. Microsoft Purview, Intune security controls, email security, and endpoint ...

2nd / 3rd Line Security Analyst

Hiring Organisation
XACT PLACEMENTS LIMITED
Location
Reading, Berkshire, South East, United Kingdom
Employment Type
Permanent
Salary
£60,000
incidents from triage through to closure Hands-on experience writing and tuning SIEM detection logic, with a solid understanding of MITRE ATT&CK and KQL (or equivalent) Practical scripting/automation experience (Python, Logic Apps, REST APIs) or hands-on SOAR platform configuration Working knowledge of several of: Microsoft Sentinel ...

Cyber Security Engineer (Threat Detection & Automation)

Hiring Organisation
Additional Resources
Location
London, United Kingdom
Salary
£ 70 K
monitoring across cloud platforms, SaaS, and internal systems.Documenting security processes, tool configurations, and contributing to service delivery documentation.Supporting colleagues with ISO 27001 compliance and KQL-related tasks.What we are looking for:Previously worked as a Threat Detection Engineer or in a similar role.Must have strong expertise in KQL.Hands-on experience ...

Cyber Security Engineer (Threat Detection & Automation)

Hiring Organisation
Additional Resources
Location
London, UK
Employment Type
Full-time
cloud platforms, SaaS, and internal systems. Documenting security processes, tool configurations, and contributing to service delivery documentation. Supporting colleagues with ISO 27001 compliance and KQL-related tasks. What we are looking for: Previously worked as a Threat Detection Engineer or in a similar role. Must have strong expertise in KQL.Hands ...

Security Operations Analyst (SOC analyst)

Hiring Organisation
JP Morgan Chase
Location
London, United Kingdom
Salary
£ 100 K
shift rotation (approximately once every five weeks).Preferred Qualifications, Capabilities, and SkillsExperience with detection engineering and writing/tuning detection content (e.g., Sigma, YARA, KQL, SPL, or equivalent).Hands-on threat hunting experience using hypothesis-driven methodologies.Familiarity with SOAR platforms, scripting/automation, and AI-assisted security tooling.Experience defending large ...

Security Operations Analyst (SOC analyst)

Location
Greater London, England, United Kingdom
approximately once every five weeks). Preferred Qualifications, Capabilities, and Skills Experience with detection engineering and writing/tuning detection content (e.g., Sigma, YARA, KQL, SPL, or equivalent). Hands-on threat hunting experience using hypothesis-driven methodologies. Familiarity with SOAR platforms, scripting/automation, and AI-assisted security tooling. ...