76 to 100 of 101 Kusto Query Language Jobs in the UK

Microsoft Security Engineer

Location
Basildon, England, United Kingdom
security controls. Key Responsibilities Design, implement and optimise Microsoft Sentinel environments, including onboarding, configuration and continuous improvement Develop and tune Sentinel analytics rules using KQL, improving detection coverage and reducing false positives Support security monitoring, threat detection and incident investigation across enterprise environments Configure and enhance Microsoft Defender XDR capabilities … produce security documentation, recommendations and implementation plans Required Experience Strong commercial experience within Microsoft security engineering roles Hands-on experience with Microsoft Sentinel, including KQL, detection engineering and SIEM optimisation Strong knowledge of Microsoft Defender XDR security capabilities Experience with Microsoft Purview DLP, sensitivity labels and information protection Strong understanding ...

Senior Microsoft Security Architect: Azure & Sentinel

Location
Basildon, England, United Kingdom
Sentinel, Defender XDR and Microsoft Purview, delivering scalable security solutions and improving detection coverage. The role requires hands-on experience with Sentinel analytics using KQL, Defender XDR capabilities, Azure security controls and IAM with Entra ID. #J-18808-Ljbffr ...

Security Engineer

Hiring Organisation
Tiro Partners Limited
Location
London, South East England, United Kingdom
Employment Type
Full-Time
Salary
£60,000 - £90,000 per annum
identify and remediate vulnerabilities. About you You’ll have strong hands-on experience in application security and ideally: Terraform and Python skills, with KQL advantageous. Experience securing GitHub/GitHub Actions, Kubernetes and APIs. Strong knowledge of application security testing and vulnerability management. Experience with DevSecOps, threat modelling and security ...

Security Engineer

Hiring Organisation
LT Harper Recruitment Group
Location
United Kingdom
engineers What you'll need Essential: A solid background as a Security Engineer or SOC Engineer Hands-on experience with Microsoft Security technologies and KQL Experience with SIEM platforms, for example Sentinel, Splunk, Rapid7 or LogRhythm Ability to lead and design automation and scripting in SIEM tools Experience analysing cloud ...

Senior SOC Analyst

Location
Greater London, England, United Kingdom
confirm investigation workflows and expected outcomes. Analyse attacker tactics, techniques and procedures (TTPs) and ensure detection content remains aligned with emerging threats. Utilise KQL, SPL, SQL, log analysis, event correlation, and telemetry investigation to validate detection's and support investigations. Support continuous improvement of detection and response capabilities. Stakeholder Management … understanding of attacker tactics, techniques and procedures (TTPs). Experience mapping detections to recognised threat frameworks such as MITRE ATT&CK . Experience using KQL, SPL, SQL , or similar query languages for investigation, threat hunting, and alert validation. Ability to define escalation criteria and investigation workflows. Experience working across ...

Remote UK: Threat Detection Content Engineer

Location
United Kingdom
candidates will have 5-8 years in detection engineering or related roles, with deep expertise in Microsoft Sentinel, 365 Defender, Logic Apps, and strong KQL skills. #J-18808-Ljbffr ...

Cyber Security Operations Lead

Hiring Organisation
Sanderson Recruitment
Location
South West, United Kingdom
Employment Type
Contract
Contract Rate
£550 - £575 per day
Cyber Security Operations - 6 months - Umbrella - 2 days on site in Head Office per week - £550/£575 Sentinel/Defender XDR and KQL proficient Able to pick up new tooling Outstanding communication skills Nice to haves but not essential Proofpoint, Tenable, Secure web gateway, purview. Role is monitor ...

Cyber Security Operations Lead

Hiring Organisation
Sanderson
Location
South West England, United Kingdom
Employment Type
Full-Time
Salary
£550.00 - £575.00 per day
Cyber Security Operations - 6 months - Umbrella - 2 days on site in Head Office per week - £550/£575 Sentinel/Defender XDR and KQL proficient Able to pick up new tooling Outstanding communication skills Nice to haves but not essential Proofpoint, Tenable, Secure web gateway, purview. Role is monitor ...

Cloud FinOps Analyst

Hiring Organisation
Manufacturing Recruitment Limited
Location
City of London, London, United Kingdom
Employment Type
Permanent
Salary
£60,000
models and platform fundamentals (Azure, Snowflake, Kubecost desirable). Experience with FinOps practices and cost management tools, particularly Kubecost and cloud-native cost portals (KQL desirable). Demonstrated ability to work cross-functionally with Finance and technical teams to support cost visibility and decision-making. ...

Senior Data Engineer

Location
Greater Manchester, England, United Kingdom
Agilisys is at the forefront of digital transformation and innovation in the public services sector. With over two decades of experience, we have established ourselves as a trusted partner for governments, local authorities, and organizations ...

Cloud Operations Manager

Location
Dudley, England, United Kingdom
including escalation handling, stakeholder communication and corrective action tracking. Ability to report findings, operational analysis, service performance and improvement recommendations in clear and concise language to technical and non-technical stakeholders. Ability to work closely with cross functional teams on shared deployment, release, incident and customer experience objectives. Creative … APIs including Swagger, OAuth2 and ODATA. Experience with Relational DBMS systems including SQL and T-SQL. Experience with Azure Monitoring and Log Analytics, notably KQL, Python and PowerShell. Location: This role may be based in either our Dudley, United Kingdom office or our Plzeň, Czech Republic office. While the position ...

Graduate SOC Analyst

Hiring Organisation
CyPro
Location
City of London, London, United Kingdom
JIRA Service Management. Detection Engineering Develop and implement new detection rules in Microsoft Sentinel aligned to the MITRE ATT&CK framework. Draft and optimise KQL queries for detection and threat hunting. Refine existing detection logic based on false positive analysis and threat evolution. Threat Intelligence & Enrichment Analyse threat intelligence feeds … hour) of Canary Wharf, London Technical Skills Familiarity with scripting and automation development (you do not need to be fluent in any particular coding language, but you should be able to demonstrate an understanding of how scripting and other tools (such as AI agents) can be used to streamline ...

Principal Security Engineer

Hiring Organisation
Hastings Direct
Location
Bexhill-on-Sea, East Sussex, UK
Employment Type
Full-time
We're a digital insurance provider with ambitious plans to become The Best and Biggest in the UK market. Over the past few years, we've made significant investments in our data and tech capabilities ...

Senior SOC Analyst (Outside IR35)

Location
West Midlands, England, United Kingdom
encryption. Ability to think critically under pressure and respond effectively to fast-moving security incidents. Scripting or query experience is highly desirable (SPL, KQL, etc.). Good communication skills from previous roles. Due to the nature and urgency of this post, candidates holding or who have held high level ...

Senior Detection Engineer (Consultancy)

Hiring Organisation
Fazer Recruitment
Location
Reading, Berkshire, United Kingdom
Employment Type
Full-Time
Salary
£85,000 - £90,000 per annum
clearance requirement. What you'll be doing Designing and building detection rulesets across SIEM and XDR platforms Writing and tuning detection logic in KQL, cutting false positives without losing coverage Mapping customer log sources against use cases to identify and close coverage gaps Designing use cases aligned to MITRE … workshops, coverage assessments and use case catalogues as customer deliverables What we're looking for Hands-on SIEM engineering experience, ideally Microsoft Sentinel Confident KQL — this is the core of the role SOAR playbook design in Azure Logic Apps, Cortex XSOAR or similar Scripting in Python or PowerShell, and comfort ...

Cyber Security Threat Hunter

Hiring Organisation
Proactive Appointments
Location
Hampshire, United Kingdom
Employment Type
Permanent
Salary
GBP 60,000 - 68,000 Annual
Experience translating hunts and red team findings into practical detections and improvements (signal selection, tuning, suppression/thresholding, entity mapping, documentation, and operational handoff) KQL depth and query performance: Comfortable using joins/unions, parsing, time-windowing, summarisation, Essential baselining, and performance-aware query patterns for large datasets ...

SOC Analyst - Active SC required

Location
Essex, England, United Kingdom
Experience within a Security Operations Centre (SOC) Proficiency with IBM QRadar SIEM for monitoring and incident response Familiarity with common query languages, preferably KQL Understanding of security processes and controls in enterprise environments Ability to work independently with minimal supervision Technical skills in Microsoft Defender, Microsoft Sentinel ...

Cyber Security Engineer

Location
Greater London, England, United Kingdom
across the estate. Perform second-line investigations of alerts escalated by the MDR provider across Defender XDR and Sentinel, conducting proactive threat hunting via KQL queries and Sentinel workbooks. Oversee the outsourced vulnerability scanning service, driving findings through to remediation within SLA limits while quality-checking triage decisions and provider … automate security operations using PowerShell and Microsoft Graph as a minimum, with ideal exposure to Logic Apps or Azure Functions. Proficiency in writing KQL queries and leveraging Sentinel workbooks to establish incident scope, impact, and root cause. Clear written and verbal communication, with the ability to translate technical security risks ...

Senior SOC Manager – Managed Cyber Defence

Location
Glasgow, Scotland, United Kingdom
Line of Service Assurance Industry/Sector Not Applicable Specialism Risk Management Level Senior Manager Job Description & Summary About the role: We are seeking a Senior Manager to lead the day-to-day technical delivery ...

SOC Engineer

Hiring Organisation
4Square Recruitment Ltd
Location
Cambridge, Cambridgeshire, United Kingdom
Employment Type
Full-Time
Salary
£40,000 - £80,000 per annum
capability What we’re looking for: Strong SOC/Security Operations experience Hands-on SIEM engineering experience Detection engineering and alert tuning Experience with KQL, SQL or similar query languages Linux experience Threat hunting and incident response experience Scripting/automation using Python and/or PowerShell Exposure ...

Senior SOC Engineer

Hiring Organisation
Fazer Recruitment
Location
Cardiff, South Glamorgan, United Kingdom
Employment Type
Full-Time
Salary
£65,000 - £70,000 per annum, Inc benefits
doing Designing and maintaining the SIEM and XDR platform — data ingestion, log parsing and normalisation, retention, performance Writing and tuning detections in KQL, and building automation to cut manual analyst effort Scripting custom connectors and integrations across the security toolset Leading the technical onboarding of new customers alongside SOC Operations … looking for Around 3–5 years in a Security Operations Centre in an engineering or platform capacity Strong Microsoft Sentinel experience, with confident KQL Hands-on with Microsoft Defender and the wider Microsoft security stack — Intune, Entra ID, Defender for Endpoint Exposure to endpoint tooling such as CrowdStrike, Carbon Black ...

Cyber Security Analyst - Microsoft Security / IAM - Contract

Hiring Organisation
Searchability
Location
Bristol, Avon, United Kingdom
Employment Type
Full-Time
Salary
£400.00 - £500.00 per day
Working with Entra ID, MFA, Conditional Access and RBAC Using Microsoft Sentinel to monitor and investigate security events and incidents Writing and working with KQL queries Investigating suspicious activity, security incidents and emerging threats Supporting vulnerability management and remediation activity Working across the wider Microsoft security ecosystem Identifying opportunities … with: Microsoft Entra ID/Azure AD Identity & Access Management (IAM) Conditional Access Multi-Factor Authentication (MFA) Role-Based Access Control (RBAC) Microsoft Sentinel KQL/custom SIEM queries Microsoft 365/Microsoft security technologies Security incident investigation and remediation Vulnerability management Network and infrastructure security Windows and Linux environments ...

Performance & Observability Engineer

Location
Greater London, England, United Kingdom
Collaborate with SRE and DevOps teams to optimise CI/CD pipelines for performance improvements. Collaborate with wider IT teams to Implement caching strategies, query optimisation, and autoscaling to enhance system efficiency. Observability Platform Development & Implementation Design and implement end-to-end observability frameworks covering metrics, logs, traces … cloud expenses. Qualifications, Skills and Experience Technical Skills Experience in using and maintaining Observability & APM Tools – Grafana experience is essential Experience of using KQL Performance Testing & Load Testing Cloud & Infrastructure Monitoring – AWS CloudWatch, Azure Monitor, GCP Operations Suite, Kubernetes Observability. Knowledge of Log Aggregation & Analysis – eg: Grafana Loki, Splunk ...

Lead Security Analyst

Location
United Kingdom
bench of analysts who can operate at the same standard. Key responsibilities Set the detection engineering standard — author, tune, and peer‐review detections in KQL, SPL, EQL, or Sigma; manage the false‐positive backlog; map coverage to MITRE ATT&CK; and train L1/L2 analysts to write and tune … Security Manager (CISM) CompTIA Advanced Security Practitioner (CASP+) Experience leading detection engineering in a SOC or similar environment— including writing and tuning detections in KQL, SPL, EQL, or Sigma, and managing coverage against MITRE ATT&CK Experience designing or improving a log and telemetry pipeline, including application‐level telemetry from ...

Senior Security Specialist - Threat Hunting

Hiring Organisation
Yolk Recruitment Limited
Location
Cardiff, South Glamorgan, Wales, United Kingdom
Employment Type
Permanent
hypothesis-driven approaches. Investigate complex security incidents and provide technical escalation within the CSOC. Develop and optimise SIEM detections, analytics, use cases and KQL queries to improve threat detection and reduce false positives. Identify gaps in logging, monitoring and telemetry across cloud, identity, endpoint, network and application environments. Analyse threat … related technical discipline. Strong knowledge of cyber security operations, threat hunting, incident response and security monitoring. Experience with SIEM platforms (ideally Microsoft Sentinel), KQL or similar analytics tools. Good understanding of cloud, endpoint, identity, network and application security. Knowledge of security frameworks such as NIST or ISO 27001. Experience Proven ...