1 to 25 of 105 Permanent Kusto Query Language Jobs in England

Tier 2 SOC Analyst- Cyber Threat Analysis Center

Location
South Kesteven, England, United Kingdom
Tier 1 Analysts, determining threat severity and advising on initial response actions. Apply expertise in SIEM solutions utilizing Kusto Query Language (KQL), to perform log analysis, event correlation, and thorough documentation of security incidents. Identify and escalate critical threats to Tier 3 Analysts with detailed analysis … analysis; some exposure to additional analysis tools such as basic XDR platforms. Able to demonstrate proficient knowledge using Kusto Query Language (KQL) to search and filter logs effectively. Familiar with open-source intelligence (OSINT) techniques to aid in identifying potential threats and gathering information. Able to communicate ...

SIEM Engineer (SC Clearance required)

Location
London, United Kingdom
LogRhythm expertise Check Point knowledge Experience developing Logic Apps, Playbooks and SOAR automation workflows. Experience onboarding and integrating diverse data sources Strong knowledge of KQL (Kusto Query Language), advanced query development and optimisation. Desirable skills: SANS SEC503 - Network Monitoring and Threat Detection. Please submit your updated ...

Security Content Engineer

Location
Greater London, England, United Kingdom
expertise in a fast-paced, collaborative environment. What You'll Do: Own and Enhance Detection Content:Autonomously develop, test, andmaintainhigh-fidelity detection logic in KQL for the Microsoft Sentinel environment. You will own a portfolio of content, ensuring its long-term effectiveness and performance. Conduct Advanced Tuning & Optimization:Perform independent … creation. Deep, hands-onexpertisewith the Microsoft security stack, including Microsoft Sentinel, Microsoft 365 Defender, and Logic Apps. Highproficiencyin Kusto Query Language (KQL), with proven experience writing complex, optimized queries for detection and hunting. Strong,demonstratedexperience automating security workflowsusing SOAR platforms, APIs, or scripting languages (Python, PowerShell). ...

Senior Cyber Threat Intelligence (CTI) Analyst

Location
Greater London, England, United Kingdom
attacker tooling using sandbox or detonation environments and extracting IOCs, C2 infrastructure, and behavioural indicators. Proficiency in at least one query language (KQL, SPL, CQL, SQL), the ability to read and understand code, and working scripting ability (e.g., Python, Bash) for enrichment and automation. Strong written and verbal ...

Automation Engineer

Hiring Organisation
Sopra Steria
Location
Farnborough, Hampshire, United Kingdom
Employment Type
Full-Time
Salary
£55,000 - £60,000 per annum
cloud-based engineering principles. It would be great if you had: Experience in Cyber Security, SOC or Security Engineering environments. Microsoft Sentinel experience. KQL, SQL or other query language knowledge. Power BI data modelling, DAX and Power Query experience. Logic Apps, Power Automate or Azure Automation. Terraform ...

Senior Cyber Security Analyst

Hiring Organisation
Lightsource bp
Location
London, United Kingdom
Salary
£ 80 K
Security Operations Center (SOC) or incident response role Advanced proficiency with Microsoft Defender XDR and expert-level knowledge of Microsoft Sentinel, including KQL query writing and analytics rule development Strong hands-on experience with Microsoft Defender for Endpoint, including policy configuration and threat investigation Demonstrable experience responding to cyber ...

Threat Intelligence Analyst

Location
Greater London, England, United Kingdom
sharing platforms, and dark web monitoring tools Correlate external intelligence with internal security events using Microsoft Sentinel and Microsoft Defender Develop and maintain advanced KQL queries for threat hunting, detection engineering, and incident investigation Produce actionable threat intelligence reports, threat actor profiles, IoCs, and executive briefings Support and participate … methodologies, and intelligence frameworks such as MITRE ATT&CK, the Diamond Model, and Cyber Kill Chain Advanced knowledge of Microsoft Sentinel, Microsoft Defender, and KQL for threat hunting and investigation Experience working with threat intelligence platforms and dark web monitoring solutions, such as DarkIQ or equivalent Strong analytical skills with ...

Lead Platform Operations Engineer

Location
Greater London, England, United Kingdom
Networking, Security, Data) Strong hands-on experience with Kubernetes, Docker, and container orchestration Expertise in Infrastructure as Code (Terraform) and scripting (PowerShell, Bash, SQL, KQL) Proven delivery of CI/CD pipelines (Azure DevOps YAML essential) Experience implementing security tooling (SAST, DAST, container scanning, WAF) Strong knowledge of cloud security ...

Manager - Cyber Security Specialist

Location
West of England, England, United Kingdom
government). Knowledge of secure system integration and API security. Strong working knowledge of SOC processes and SIEM engineering, preferably using Microsoft Sentinel (KQL, analytics rule tuning, workbooks, automation) and Microsoft Defender security tools. Understanding of supply chain security risks. SC clearance. QUALIFICATIONS & CERTIFICATIONS Degree in Cyber Security ...

SIEM Engineer (SC Cleared)

Location
Reading, England, United Kingdom
Microsoft Sentinel to ensure complete and reliable security telemetry Develop custom parsers and data transformations to normalise and enrich ingested data Design and optimise KQL queries to support effective threat detection and investigation Create and maintain analytic rules and detection logic aligned to emerging threats and business use cases Develop ...

SIEM Engineer (SC Cleared)

Location
Havant, England, United Kingdom
Microsoft Sentinel to ensure complete and reliable security telemetry Develop custom parsers and data transformations to normalise and enrich ingested data Design and optimise KQL queries to support effective threat detection and investigation Create and maintain analytic rules and detection logic aligned to emerging threats and business use cases Develop ...

SIEM Engineer (SC Cleared)

Hiring Organisation
Lorien
Location
Reading, Berkshire, United Kingdom
Employment Type
Full-Time
Salary
Salary negotiable
Microsoft Sentinel to ensure complete and reliable security telemetry Develop custom parsers and data transformations to normalise and enrich ingested data Design and optimise KQL queries to support effective threat detection and investigation Create and maintain analytic rules and detection logic aligned to emerging threats and business use cases Develop ...

2nd / 3rd Line Security Analyst

Hiring Organisation
XACT PLACEMENTS LIMITED
Location
Reading, Berkshire, South East, United Kingdom
Employment Type
Permanent
Salary
£60,000
incidents from triage through to closure Hands-on experience writing and tuning SIEM detection logic, with a solid understanding of MITRE ATT&CK and KQL (or equivalent) Practical scripting/automation experience (Python, Logic Apps, REST APIs) or hands-on SOAR platform configuration Working knowledge of several of: Microsoft Sentinel ...

Cyber Security Engineer (Threat Detection & Automation)

Hiring Organisation
Additional Resources
Location
London, United Kingdom
Salary
£ 70 K
monitoring across cloud platforms, SaaS, and internal systems.Documenting security processes, tool configurations, and contributing to service delivery documentation.Supporting colleagues with ISO 27001 compliance and KQL-related tasks.What we are looking for:Previously worked as a Threat Detection Engineer or in a similar role.Must have strong expertise in KQL.Hands-on experience ...

Cyber Security Engineer (Threat Detection & Automation)

Hiring Organisation
Additional Resources
Location
London, UK
Employment Type
Full-time
cloud platforms, SaaS, and internal systems. Documenting security processes, tool configurations, and contributing to service delivery documentation. Supporting colleagues with ISO 27001 compliance and KQL-related tasks. What we are looking for: Previously worked as a Threat Detection Engineer or in a similar role. Must have strong expertise in KQL.Hands ...

Logs Specialist

Location
Maidenhead, England, United Kingdom
proactively provide technical guidance to unlock more log data volume and user adoption.* Conduct "Best Practice" workshops focused on log-based alerting, DQL (Dynatrace Query Language) proficiency, and dashboarding.## **What will help you succeed****Qualifications & Requirements*** Experience: 5+ years in a domain, specialist, pre-sales, professional services … role, with at least 3 years specifically focused on Log Management or Big Data analytics.* Technical Depth: Advanced proficiency in Query Languages (e.g., Splunk SPL, Kusto QL, SQL, or Lucene).* Deep understanding of Log Ingestion pipelines and "Telemetry Pipelines" (Cribl, BindPlane, Vector).* Hands-on experience with ...

SOC Analyst

Location
Harlow, England, United Kingdom
QRadar SIEM Experience monitoring, triaging, and investigating security incidents Knowledge of incident response lifecycle and root cause analysis Experience with Microsoft Defender (essential) KQL knowledge desirable Ability to work independently and manage complex cyber investigations Technical Exposure: IBM QRadar Microsoft Defender/EDR Microsoft Sentinel (desirable) Microsoft Entra ID/ ...

Associate Security Analyst

Hiring Organisation
NonStop Consulting Ltd
Location
London, South East England, United Kingdom
Employment Type
Full-Time
Salary
£650.00 - £700.00 per day
Analyst. Hands-on experience with SIEM (Splunk preferred; Microsoft Sentinel or equivalent also considered). Experience with M365 security tooling (e.g. Microsoft Defender, Sentinel, KQL). Good understanding of threat actors' tools, techniques and procedures . Strong analytical, problem-solving and communication skills. Nice to have Further experience with Splunk ...

Security Operations Analyst (SOC analyst)

Hiring Organisation
JP Morgan Chase
Location
London, United Kingdom
Salary
£ 100 K
shift rotation (approximately once every five weeks).Preferred Qualifications, Capabilities, and SkillsExperience with detection engineering and writing/tuning detection content (e.g., Sigma, YARA, KQL, SPL, or equivalent).Hands-on threat hunting experience using hypothesis-driven methodologies.Familiarity with SOAR platforms, scripting/automation, and AI-assisted security tooling.Experience defending large ...

Security Operations Analyst (SOC analyst)

Location
Greater London, England, United Kingdom
approximately once every five weeks). Preferred Qualifications, Capabilities, and Skills Experience with detection engineering and writing/tuning detection content (e.g., Sigma, YARA, KQL, SPL, or equivalent). Hands-on threat hunting experience using hypothesis-driven methodologies. Familiarity with SOAR platforms, scripting/automation, and AI-assisted security tooling. ...

SC-Cleared SIEM Engineer: Sentinel & SOAR Automation

Location
Reading, England, United Kingdom
onboard and integrate security log sources into Microsoft Sentinel, delivering reliable telemetry and comprehensive threat visibility. You will develop custom parsers, transformations and KQL queries, and design SIEM detections aligned to evolving threats. CI/CD pipelines with Azure DevOps/Git enable controlled deployments. #J-18808-Ljbffr ...

Cyber Security Analyst

Location
Bath, England, United Kingdom
Experience working with SIEM, EDR, vulnerability management, and identity and access management solutions. Knowledge of Microsoft Purview, DLP policy creation and reporting Knowledge of KQL and JSON for queries and automation Core Competencies Analytical & Problem-Solving Skills: Ability to assess complex security issues and develop practical, risk-based solutions. Communication ...

Azure Platform Architect

Location
Slough, England, United Kingdom
Policy, Management Groups and subscription architecture Azure Migrate and associated discovery tooling Microsoft Defender for Cloud and Microsoft Sentinel Azure Monitor, Log Analytics and KQL Zero Trust architecture High availability and disaster recovery FinOps and cloud cost optimisation Use of GitHub Copilot to accelerate Infrastructure as Code development The Person ...

Azure Platform Architect

Location
Greater London, England, United Kingdom
Policy, Management Groups and subscription architecture Azure Migrate and associated discovery tooling Microsoft Defender for Cloud and Microsoft Sentinel Azure Monitor, Log Analytics and KQL Zero Trust architecture High availability and disaster recovery FinOps and cloud cost optimisation Use of GitHub Copilot to accelerate Infrastructure as Code development The Person ...

Data Governance Managing Consultant

Location
Greater London, England, United Kingdom
Enterprise architecture frameworks (TOGAF, SABSA, or equivalent)Strong understanding of data classification models, and risk scoringAbility to design and optimise enterprise Purview deploymentsKnowledge of KQL, PowerShell, and Microsoft Graph is a plus.Capability to analyse unstructured and structured data estatesAbility to lead technical teams and influence senior leadershipAbility to work across ...