51 to 75 of 102 Kusto Query Language Jobs in the UK

Identity & Access Security Analyst – Microsoft IAM & Sentinel

Location
West of England, England, United Kingdom
/Azure AD, Conditional Access, MFA and RBAC, with hands-on work in Microsoft Sentinel. You will monitor security events, investigate incidents, write KQL queries, and collaborate with internal teams and third-party security providers to improve the #J-18808-Ljbffr ...

SC-Cleared SIEM Engineer — Microsoft Sentinel Expert

Location
Reading, England, United Kingdom
specialist SIEM Engineer with active SC clearance to enhance and automate its Microsoft Sentinel platform. You will onboard log sources, build parsers, optimise KQL queries and design detection logic. The role involves developing Logic Apps/Playbooks and setting up CI/CD pipelines for secure deployments across environments. ...

Security Analyst

Location
Greater London, England, United Kingdom
Required Proven experience in Security Operations or Cyber Security. Hands‐on experience with Splunk, log forwarding and SIEM administration. Strong analytical skills using SPL, KQL and/or SQL. Experience investigating security incidents, insider threats or data exfiltration. Knowledge of vulnerability management and security assurance within enterprise environments. #J ...

Senior Security Operations Analyst

Hiring Organisation
DGH Recruitment
Location
Leeds, West Yorkshire, Yorkshire, United Kingdom
Employment Type
Permanent
Salary
£90,000
triage, threat hunting, data loss prevention, and operational risk analysis. * Demonstrable experience with at least one major SIEM and EDR platform, additional hands on KQL/SPL, PowerShell/Python experience preferred. * Demonstrable experience with Security Orchestration and Automation. * Certifications such as SC-200, AZ-500, GCIA/GCIH/ ...

Performance and Monitoring Engineer

Hiring Organisation
Solus Accident Repair Centres
Location
Birchanger, Hertfordshire, United Kingdom
Employment Type
Permanent
Salary
GBP 40,000 - 50,000 Annual
Analytics, Defender for Cloud) Excellent understanding of cloud performance, IaaS/PaaS, networking fundamentals, API performance and capacity modelling Skilled in dashboards, log queries (KQL), custom metrics and performance analysis Ability to diagnose complex issues across infrastructure, networks, applications or databases Confident scripting and automation skills (PowerShell, Azure Automation, Graph ...

Performance and Monitoring Engineer

Hiring Organisation
Solus Accident Repair Centres
Location
Stansted, Essex, South East, United Kingdom
Employment Type
Permanent
Salary
£50,000
Analytics, Defender for Cloud) Excellent understanding of cloud performance, IaaS/PaaS, networking fundamentals, API performance and capacity modelling Skilled in dashboards, log queries (KQL), custom metrics and performance analysis Ability to diagnose complex issues across infrastructure, networks, applications or databases Confident scripting and automation skills (PowerShell, Azure Automation, Graph ...

Senior Detection & Threat Engineer

Hiring Organisation
Checkout.com
Location
London, UK
Employment Type
Full-time
intrusion techniques across the attack lifecycleHands-on experience buidling detection logic in modern SIEM platforms (e.g Sentinel)Proficienty with scripting and programmaining (e.g. Python, KQL) to build detection pipelines and automationWillingness to challenge bad detections, weak assumptions, and vanity metricsPragmatic mindset: precision and impact beat coverage theatreExperience operating beyond traditional ...

Senior Microsoft Security Architect: Azure & Sentinel

Location
Basildon, England, United Kingdom
Sentinel, Defender XDR and Microsoft Purview, delivering scalable security solutions and improving detection coverage. The role requires hands-on experience with Sentinel analytics using KQL, Defender XDR capabilities, Azure security controls and IAM with Entra ID. #J-18808-Ljbffr ...

Microsoft Security Engineer

Location
Basildon, England, United Kingdom
security controls. Key Responsibilities Design, implement and optimise Microsoft Sentinel environments, including onboarding, configuration and continuous improvement Develop and tune Sentinel analytics rules using KQL, improving detection coverage and reducing false positives Support security monitoring, threat detection and incident investigation across enterprise environments Configure and enhance Microsoft Defender XDR capabilities … produce security documentation, recommendations and implementation plans Required Experience Strong commercial experience within Microsoft security engineering roles Hands-on experience with Microsoft Sentinel, including KQL, detection engineering and SIEM optimisation Strong knowledge of Microsoft Defender XDR security capabilities Experience with Microsoft Purview DLP, sensitivity labels and information protection Strong understanding ...

Cloud Support Engineer

Location
United Kingdom
Please note that for this role, you must be based in the UK, Malta, Bulgaria or Portugal. About Us Ascent has recently been acquired by Acuity Analytics , marking an exciting new chapter for our business ...

24/7 SOC Analyst

Location
Basingstoke, England, United Kingdom
Experience with Microsoft Sentinel, Google SecOps or other SIEM platforms. Experience with Defender, CrowdStrike, SentinelOne or other XDR solutions. Ability to query in KQL, CQL, S1QL, XQL or similar languages. Awareness of threat intelligence concepts and application to investigations. Awareness of coding or scripting, with proficiency in at least … language preferred (but not required). Job Specifics Location: This role is home‐based with occasional visits to the office in Basingstoke Hours: 12‐hour shifts: 2 days, 2 nights; 4 days/nights off. Flexibility with hours will be required in the event of a major incident Security ...

Senior SOC Analyst

Location
England, United Kingdom
confirm investigation workflows and expected outcomes. Analyse attacker tactics, techniques and procedures (TTPs) and ensure detection content remains aligned with emerging threats. Utilise KQL, SPL, SQL, log analysis, event correlation, and telemetry investigation to validate detection's and support investigations. Support continuous improvement of detection and response capabilities. Stakeholder Management … understanding of attacker tactics, techniques and procedures (TTPs). Experience mapping detections to recognised threat frameworks such as MITRE ATT&CK . Experience using KQL, SPL, SQL , or similar query languages for investigation, threat hunting, and alert validation. Ability to define escalation criteria and investigation workflows. Experience working across ...

Cyber Operations Security Engineer

Hiring Organisation
Softcat
Location
Manchester, United Kingdom
efficiency across the platforms in use and surrounding technical practicesDeliver end‐to‐end SIEM/Sentinel engineering by onboarding customers, configuring data connectors, integrations, KQL, automation, dashboards and reporting.Implement tuning, enrichment and optimisation across Sentinel and align with other SIEM tools.Maintain SIEM ingestion pipeline reliability by investigating and resolving issues ...

Cyber Operations Security Engineer

Location
Manchester, England, United Kingdom
across the platforms in use and surrounding technical practices Deliver end‐to‐end SIEM/Sentinel engineering by onboarding customers, configuring data connectors, integrations, KQL, automation, dashboards and reporting. Implement tuning, enrichment and optimisation across Sentinel and align with other SIEM tools. Maintain SIEM ingestion pipeline reliability by investigating ...

Security Consultant

Location
Greater London, England, United Kingdom
delivering detection engineering engagements, including: Designing and implementing high-quality detection rules across SIEM and XDR platforms. Creating and optimising detection logic using KQL and other query languages. Developing detection use cases aligned with the MITRE ATT&CK framework and current threat techniques. Assessing customer telemetry and identifying opportunities … complex problems and working closely with customers. You’ll ideally have experience with: SIEM engineering, preferably Microsoft Sentinel. Detection engineering and rule development using KQL or similar languages. SOAR platforms such as Microsoft Logic Apps, Cortex XSOAR or equivalent. Python, PowerShell or other scripting languages for automation and API integration. ...

Security Detection & Response Specialist

Location
Chester, England, United Kingdom
experience with log analysis and telemetry interpretation, including familiarity with querying or analyzing data using tools such as SIEM platforms or query languages (KQL, SPL, SQL, or similar) Exposure to security platforms and technologies such as SIEM, EDR/XDR, identity systems, or cloud environments Foundational understanding of common ...

Cyber Security Operations Lead

Hiring Organisation
Sanderson Recruitment
Location
United Kingdom
Employment Type
Contract
Contract Rate
GBP 550 - 575 Daily
Cyber Security Operations - 6 months - Umbrella - 2 days on site in Head Office per week - £550/£575 Sentinel/Defender XDR and KQL proficient Able to pick up new tooling Outstanding communication skills Nice to haves but not essential Proofpoint, Tenable, Secure web gateway, purview. Role is monitor ...

Remote UK: Threat Detection Content Engineer

Location
United Kingdom
candidates will have 5-8 years in detection engineering or related roles, with deep expertise in Microsoft Sentinel, 365 Defender, Logic Apps, and strong KQL skills. #J-18808-Ljbffr ...

Cyber Security Operations Lead

Hiring Organisation
Sanderson Recruitment
Location
South West, United Kingdom
Employment Type
Contract
Contract Rate
£550 - £575 per day
Cyber Security Operations - 6 months - Umbrella - 2 days on site in Head Office per week - £550/£575 Sentinel/Defender XDR and KQL proficient Able to pick up new tooling Outstanding communication skills Nice to haves but not essential Proofpoint, Tenable, Secure web gateway, purview. Role is monitor ...

Cloud FinOps Analyst

Location
Tonbridge, England, United Kingdom
models and platform fundamentals (Azure, Snowflake, Kubecost desirable). Experience with FinOps practices and cost management tools, particularly Kubecost and cloud‐native cost portals (KQL desirable). Demonstrated ability to work cross‐functionally with Finance and technical teams to support cost visibility and decision‐making #J-18808-Ljbffr ...

Cloud FinOps Analyst

Hiring Organisation
Manufacturing Recruitment Limited
Location
City of London, London, United Kingdom
Employment Type
Permanent
Salary
£60,000
models and platform fundamentals (Azure, Snowflake, Kubecost desirable). Experience with FinOps practices and cost management tools, particularly Kubecost and cloud-native cost portals (KQL desirable). Demonstrated ability to work cross-functionally with Finance and technical teams to support cost visibility and decision-making. ...

Cloud FinOps Analyst

Hiring Organisation
Hastings Direct
Location
Bexhill, United Kingdom
finding opportunities to drive value Fundamental understanding of a cloud platform and its usage and cost dynamics, with knowledge of Azure, Snowflake, Kubecost and KQL as a plus.What we will give you:Join us and you’ll find a different way of doing things. We call it the 4Cs. ...

Cloud FinOps Analyst

Hiring Organisation
Hastings Direct
Location
Bexhill, East Sussex, United Kingdom
Salary
£ 70 K
finding opportunities to drive value Fundamental understanding of a cloud platform and its usage and cost dynamics, with knowledge of Azure, Snowflake, Kubecost and KQL as a plus.What we will give you:Join us and you’ll find a different way of doing things. We call it the 4Cs. ...

Threat Detection Engineer - Hybrid / Remote

Hiring Organisation
Additional Resources
Location
London, United Kingdom
maintain and tune the detection catalogueBuild automated reporting dashboards using Microsoft Sentinel workbooksSupport security initiatives including ISO 27001 activities and KQL-based tasksEnsure monitoring coverage across cloud platforms, SaaS apps, and internal systemsContribute to documentation of processes, tools, and detection logicWhat You’ll BringMust-Have Skills & Experience:Previously worked … Threat Detection Engineer or in a similar role.Strong proficiency in KQL and hands-on experience with Microsoft SentinelFamiliarity with Microsoft Defender tools (Endpoint & O365)Exposure to Azure cloud logging and Kubernetes environmentsKnowledge of attacker TTPs and MITRE ATT&CK frameworksProactive, collaborative, and innovative mindsetDesirable/Nice-to-Have:Experience with ...