22 of 22 Kusto Query Language Jobs in London

SIEM Engineer (SC Clearance required)

Location
London, United Kingdom
LogRhythm expertise Check Point knowledge Experience developing Logic Apps, Playbooks and SOAR automation workflows. Experience onboarding and integrating diverse data sources Strong knowledge of KQL (Kusto Query Language), advanced query development and optimisation. Desirable skills: SANS SEC503 - Network Monitoring and Threat Detection. Please submit your updated ...

SIEM Engineer (SC Clearance required)

Hiring Organisation
Harvey Nash
Location
Southall, England, United Kingdom
LogRhythm expertise Check Point knowledge Experience developing Logic Apps, Playbooks and SOAR automation workflows. Experience onboarding and integrating diverse data sources Strong knowledge of KQL (Kusto Query Language), advanced query development and optimisation. Desirable skills: SANS SEC503 - Network Monitoring and Threat Detection. Please submit your updated ...

SIEM Engineer (SC Clearance required)

Hiring Organisation
Harvey Nash
Location
South Ruislip, England, United Kingdom
LogRhythm expertise Check Point knowledge Experience developing Logic Apps, Playbooks and SOAR automation workflows. Experience onboarding and integrating diverse data sources Strong knowledge of KQL (Kusto Query Language), advanced query development and optimisation. Desirable skills: SANS SEC503 - Network Monitoring and Threat Detection. Please submit your updated ...

Exchange SME

Hiring Organisation
Morson Edge
Location
London, United Kingdom
Employment Type
Contract
Contract Rate
£400 - 440 per day
Implement security best practices, including privileged access management and least privilege. Microsoft Sentinel Deploy, configure, and manage Microsoft Sentinel. Develop and maintain analytics rules, KQL queries, workbooks, and automation. Investigate security incidents and suspicious activity. Integrate Microsoft Sentinel with Active Directory, Microsoft 365, Defender, and other security platforms. Develop Logic … Services Group Policy DNS, DHCP, TCP/IP PowerShell Microsoft 365 Microsoft Entra ID Microsoft Defender Microsoft Sentinel Kusto Query Language (KQL) Windows Server Azure Hybrid identity and Exchange environments Security monitoring and incident response Please send your CV fo immediate interview ...

Senior Cyber Threat Intelligence (CTI) Analyst

Location
Greater London, England, United Kingdom
attacker tooling using sandbox or detonation environments and extracting IOCs, C2 infrastructure, and behavioural indicators. Proficiency in at least one query language (KQL, SPL, CQL, SQL), the ability to read and understand code, and working scripting ability (e.g., Python, Bash) for enrichment and automation. Strong written and verbal ...

Senior Cyber Security Analyst

Hiring Organisation
Lightsource bp
Location
London, UK
Employment Type
Full-time
Security Operations Center (SOC) or incident response role Advanced proficiency with Microsoft Defender XDR and expert-level knowledge of Microsoft Sentinel, including KQL query writing and analytics rule development Strong hands-on experience with Microsoft Defender for Endpoint, including policy configuration and threat investigation Demonstrable experience responding to cyber ...

Lead Platform Operations Engineer

Location
Greater London, England, United Kingdom
Networking, Security, Data) Strong hands-on experience with Kubernetes, Docker, and container orchestration Expertise in Infrastructure as Code (Terraform) and scripting (PowerShell, Bash, SQL, KQL) Proven delivery of CI/CD pipelines (Azure DevOps YAML essential) Experience implementing security tooling (SAST, DAST, container scanning, WAF) Strong knowledge of cloud security ...

Associate Security Analyst

Hiring Organisation
NonStop Consulting
Location
London, United Kingdom
Employment Type
Contract
Contract Rate
£650 - £700/day
Analyst. Hands-on experience with SIEM (Splunk preferred; Microsoft Sentinel or equivalent also considered). Experience with M365 security tooling (e.g. Microsoft Defender, Sentinel, KQL). Good understanding of threat actors' tools, techniques and procedures . Strong analytical, problem-solving and communication skills. Nice to have Further experience with Splunk ...

Associate Security Analyst

Hiring Organisation
NonStop Consulting Ltd
Location
London, South East England, United Kingdom
Employment Type
Full-Time
Salary
£650.00 - £700.00 per day
Analyst. Hands-on experience with SIEM (Splunk preferred; Microsoft Sentinel or equivalent also considered). Experience with M365 security tooling (e.g. Microsoft Defender, Sentinel, KQL). Good understanding of threat actors' tools, techniques and procedures . Strong analytical, problem-solving and communication skills. Nice to have Further experience with Splunk ...

Azure Platform Architect

Hiring Organisation
Cognitive Group | Part of the Focus Cloud Group
Location
City of London, London, United Kingdom
Policy, Management Groups and subscription architecture Azure Migrate and associated discovery tooling Microsoft Defender for Cloud and Microsoft Sentinel Azure Monitor, Log Analytics and KQL Zero Trust architecture High availability and disaster recovery FinOps and cloud cost optimisation Use of GitHub Copilot to accelerate Infrastructure as Code development The Person ...

Data Governance Managing Consultant

Location
Greater London, England, United Kingdom
Enterprise architecture frameworks (TOGAF, SABSA, or equivalent)Strong understanding of data classification models, and risk scoringAbility to design and optimise enterprise Purview deploymentsKnowledge of KQL, PowerShell, and Microsoft Graph is a plus.Capability to analyse unstructured and structured data estatesAbility to lead technical teams and influence senior leadershipAbility to work across ...

Senior Cyber Security Analyst

Hiring Organisation
IO Associates
Location
Central London, London, United Kingdom
Employment Type
Permanent
Salary
£70,000
senior escalation point. About you: Strong hands-on experience across security operations and incident response. Good knowledge of Microsoft security technologies , with KQL/Sentinel experience desirable. Strong understanding of IAM, endpoints, networking, cloud and enterprise security. Practical vulnerability management and cyber risk assessment experience. Experience with ISO 27001, Cyber ...

security engineer in legal services

Location
Greater London, England, United Kingdom
Sentinel, Exabeam, Splunk, or equivalent Experience with vulnerability management using Tenable or equivalent enterprise toolsets Experience with scripting and automation, preferably PowerShell, and KQL or similar Experience with Data Loss Prevention solutions, including MS Purview Compliance Manager Nice to have: CISSP, CREST Practitioner Security Analyst (CPSA), Palo Alto Networks Certified ...

Senior Security Engineer - Contract

Location
Greater London, England, United Kingdom
security risk clearly to engineering and product audiences. A growth mindset and genuine curiosity to keep learning. SC-200 (Microsoft Security Operations Analyst) certification. KQL proficiency for detection rule authoring and threat hunting. Experience working in a similar fintech or financial services environment All are welcome: #J-18808-Ljbffr ...

Senior Security Architect - SecOps and Vulnerability Management

Hiring Organisation
JP Morgan Chase
Location
London, UK
Employment Type
Full-time
advising and influencing enterprise SIEM platforms (e.g., Microsoft Sentinel, Splunk, Chronicle/SecOps). Must be proficient in writing/reviewing advanced detection logic (KQL, SPL, or YARA rules).Deep execution knowledge of generating, managing, and analyzing Software Bills of Materials (SBOMs using frameworks like CycloneDX or SPDX) and integrating ...

Senior Application Security Engineer / DevSecOps Engineer

Hiring Organisation
Additional Resources
Location
London, United Kingdom
Employment Type
Permanent
Salary
£80000 - £90000/annum
scale medical research. You will work closely with engineering, architecture and cloud teams to integrate security throughout the software development lifecycle. Microsoft Azure and KQL experience are essential, alongside relevant experience in CI/CD, Kubernetes, API security, security-as-code and security automation. This is a hands-on application ...

Security Engineer

Hiring Organisation
Tiro Partners Limited
Location
London, South East England, United Kingdom
Employment Type
Full-Time
Salary
£60,000 - £90,000 per annum
identify and remediate vulnerabilities. About you You’ll have strong hands-on experience in application security and ideally: Terraform and Python skills, with KQL advantageous. Experience securing GitHub/GitHub Actions, Kubernetes and APIs. Strong knowledge of application security testing and vulnerability management. Experience with DevSecOps, threat modelling and security ...

Senior SOC Analyst

Location
Greater London, England, United Kingdom
confirm investigation workflows and expected outcomes. Analyse attacker tactics, techniques and procedures (TTPs) and ensure detection content remains aligned with emerging threats. Utilise KQL, SPL, SQL, log analysis, event correlation, and telemetry investigation to validate detection's and support investigations. Support continuous improvement of detection and response capabilities. Stakeholder Management … understanding of attacker tactics, techniques and procedures (TTPs). Experience mapping detections to recognised threat frameworks such as MITRE ATT&CK . Experience using KQL, SPL, SQL , or similar query languages for investigation, threat hunting, and alert validation. Ability to define escalation criteria and investigation workflows. Experience working across ...

Cloud FinOps Analyst

Hiring Organisation
Manufacturing Recruitment Limited
Location
City of London, London, United Kingdom
Employment Type
Permanent
Salary
£60,000
models and platform fundamentals (Azure, Snowflake, Kubecost desirable). Experience with FinOps practices and cost management tools, particularly Kubecost and cloud-native cost portals (KQL desirable). Demonstrated ability to work cross-functionally with Finance and technical teams to support cost visibility and decision-making. ...

Graduate SOC Analyst

Hiring Organisation
CyPro
Location
City of London, London, United Kingdom
JIRA Service Management. Detection Engineering Develop and implement new detection rules in Microsoft Sentinel aligned to the MITRE ATT&CK framework. Draft and optimise KQL queries for detection and threat hunting. Refine existing detection logic based on false positive analysis and threat evolution. Threat Intelligence & Enrichment Analyse threat intelligence feeds … hour) of Canary Wharf, London Technical Skills Familiarity with scripting and automation development (you do not need to be fluent in any particular coding language, but you should be able to demonstrate an understanding of how scripting and other tools (such as AI agents) can be used to streamline ...

Cyber Security Engineer

Location
Greater London, England, United Kingdom
across the estate. Perform second-line investigations of alerts escalated by the MDR provider across Defender XDR and Sentinel, conducting proactive threat hunting via KQL queries and Sentinel workbooks. Oversee the outsourced vulnerability scanning service, driving findings through to remediation within SLA limits while quality-checking triage decisions and provider … automate security operations using PowerShell and Microsoft Graph as a minimum, with ideal exposure to Logic Apps or Azure Functions. Proficiency in writing KQL queries and leveraging Sentinel workbooks to establish incident scope, impact, and root cause. Clear written and verbal communication, with the ability to translate technical security risks ...

Performance & Observability Engineer

Location
Greater London, England, United Kingdom
Collaborate with SRE and DevOps teams to optimise CI/CD pipelines for performance improvements. Collaborate with wider IT teams to Implement caching strategies, query optimisation, and autoscaling to enhance system efficiency. Observability Platform Development & Implementation Design and implement end-to-end observability frameworks covering metrics, logs, traces … cloud expenses. Qualifications, Skills and Experience Technical Skills Experience in using and maintaining Observability & APM Tools – Grafana experience is essential Experience of using KQL Performance Testing & Load Testing Cloud & Infrastructure Monitoring – AWS CloudWatch, Azure Monitor, GCP Operations Suite, Kubernetes Observability. Knowledge of Log Aggregation & Analysis – eg: Grafana Loki, Splunk ...