1 to 25 of 98 Permanent Kusto Query Language Jobs in the UK

Tier 2 SOC Analyst- Cyber Threat Analysis Center

Location
South Kesteven, England, United Kingdom
Tier 1 Analysts, determining threat severity and advising on initial response actions. Apply expertise in SIEM solutions utilizing Kusto Query Language (KQL), to perform log analysis, event correlation, and thorough documentation of security incidents. Identify and escalate critical threats to Tier 3 Analysts with detailed analysis … analysis; some exposure to additional analysis tools such as basic XDR platforms. Able to demonstrate proficient knowledge using Kusto Query Language (KQL) to search and filter logs effectively. Familiar with open-source intelligence (OSINT) techniques to aid in identifying potential threats and gathering information. Able to communicate ...

Microsoft Security Platform Security Engineer

Location
Salford, England, United Kingdom
improvement of Microsoft Sentinel as our central security monitoring and response platform Develop and maintain detection rules, dashboards, workbooks and threat-hunting queries using KQL Create and enhance automated response playbooks using Azure Logic Apps Integrate and optimise Microsoft Defender alerts and security controls Design and implement data classification, sensitivity … Microsoft Purview Experience implementing or managing Data Loss Prevention (DLP), information protection and security monitoring solutions Proficiency in Kusto Query Language (KQL) and security analytics Experience with Azure Logic Apps, automation and Microsoft cloud security technologies Good understanding of cloud security, threat detection, incident response and cyber ...

Security Content Engineer

Location
Greater London, England, United Kingdom
expertise in a fast-paced, collaborative environment. What You'll Do: Own and Enhance Detection Content:Autonomously develop, test, andmaintainhigh-fidelity detection logic in KQL for the Microsoft Sentinel environment. You will own a portfolio of content, ensuring its long-term effectiveness and performance. Conduct Advanced Tuning & Optimization:Perform independent … creation. Deep, hands-onexpertisewith the Microsoft security stack, including Microsoft Sentinel, Microsoft 365 Defender, and Logic Apps. Highproficiencyin Kusto Query Language (KQL), with proven experience writing complex, optimized queries for detection and hunting. Strong,demonstratedexperience automating security workflowsusing SOAR platforms, APIs, or scripting languages (Python, PowerShell). ...

Security Content Engineer

Hiring Organisation
BlueVoyant
Location
United Kingdom
fast-paced, collaborative environment.What You'll Do:Own and Enhance Detection Content: Autonomously develop, test, and maintain high-fidelity detection logic in KQL for the Microsoft Sentinel environment. You will own a portfolio of content, ensuring its long-term effectiveness and performance. Conduct Advanced Tuning & Optimization: Perform independent and complex … expertise with the Microsoft security stack, including Microsoft Sentinel, Microsoft 365 Defender, and Logic Apps. High proficiency in Kusto Query Language (KQL), with proven experience writing complex, optimized queries for detection and hunting. Strong, demonstrated experience automating security workflows using SOAR platforms, APIs, or scripting languages (Python ...

Cyber Security Specialist (Operational)

Location
Manchester, England, United Kingdom
description attached for full list of responsibilities. Person Specification Knowledge Knowledge of Microsoft Defender, Sentinel, including Kusto Query Language (KQL), threat hunting, analytics rule development, security monitoring, incident investigation and automation capabilities. Education/Qualifications Holds highly developed specialist knowledge and expertise acquired through master's degree ...

Cyber Security Specialist (Operational)

Hiring Organisation
NICE – The National Institute for Health and Care Excellence
Location
Manchester, M1 3BN, United Kingdom
Salary
£57528.00 to £64750.00
description attached for full list of responsibilities. Person Specification Knowledge Desirable Knowledge of Microsoft Defender, Sentinel, including Kusto Query Language (KQL), threat hunting, analytics rule development, security monitoring, incident investigation and automation capabilities. Education/Qualifications Essential Holds highly developed specialist knowledge and expertise acquired through master ...

Security Analyst: 2nd Line

Location
Newcastle upon Tyne, England, United Kingdom
Solid understanding of networking principles and security technologies, including firewalls, WAFs, application gateways and network infrastructure. Experience using Kusto Query Language (KQL) and PowerShell to investigate, automate and improve security operations. Ability to create clear technical documentation, including security playbooks, processes and network diagrams. Self-motivated ...

Managing Engineer - Observability, Pipeline & Analytics (Hybrid)

Location
Belfast City District, Northern Ireland, United Kingdom
transformation initiatives. Desirable Skills: Experience implementing telemetry cost optimization and data reduction strategies at enterprise scale. Knowledge of Kusto Query Language (KQL) and large‐scale analytics platforms. Experience with Cribl, ADX, Datadog Pipelines, Splunk, Sentinel, Kafka, Event Hubs, Open Telemetry, Elastic, Grafana, or similar observability ecosystems. Ability ...

Senior Cyber Threat Intelligence (CTI) Analyst

Location
United Kingdom
attacker tooling using sandbox or detonation environments and extracting IOCs, C2 infrastructure, and behavioral indicators.Proficiency in at least one query language (KQL, SPL, CQL, SQL), the ability to read and understand code, and working scripting ability (e.g., Python, Bash) for enrichment and automation.Strong written and verbal communication skills ...

Senior Cyber Threat Intelligence (CTI) Analyst

Location
Greater London, England, United Kingdom
attacker tooling using sandbox or detonation environments and extracting IOCs, C2 infrastructure, and behavioural indicators. Proficiency in at least one query language (KQL, SPL, CQL, SQL), the ability to read and understand code, and working scripting ability (e.g., Python, Bash) for enrichment and automation. Strong written and verbal ...

Automation Engineer

Hiring Organisation
Sopra Steria
Location
Farnborough, Hampshire, United Kingdom
Employment Type
Full-Time
Salary
£55,000 - £60,000 per annum
cloud-based engineering principles. It would be great if you had: Experience in Cyber Security, SOC or Security Engineering environments. Microsoft Sentinel experience. KQL, SQL or other query language knowledge. Power BI data modelling, DAX and Power Query experience. Logic Apps, Power Automate or Azure Automation. Terraform ...

Technical Analyst

Location
United Kingdom
cataloguing and lineage use cases. Skills & Competencies Ability to configure and manage Purview policies and scanning tools. Strong analytical and troubleshooting skills. Familiarity with KQL, PowerShell, or Microsoft Graph. Ability to interpret logs, alerts, and governance reporting. Strong documentation and verbal communication skills. Ability to work collaboratively with cross functional ...

SOAR Engineer

Location
Warwick, England, United Kingdom
refinement. Conduct in-depth analysis of the existing functionality of the CSIRT, propose and enact improvements to the service. About you: Strong proficiency in KQL and detection engineering. Have a high level of ability to create and develop security orchestration and automated response (SOAR). Experience and working knowledge with ...

Level 3 SOC Analyst

Location
Belfast City District, Northern Ireland, United Kingdom
platforms, including IBM QRadar, Microsoft Sentinel and LogRhythm In-depth experience with Microsoft Sentinel, including use case and rule development, workbook/playbook creation, KQL & Logic Apps/SOAR Experience in managing Microsoft Sentinel as an MSSP, including Lighthouse, and management and multi-customer environments using DevOps How this aligns ...

Manager - Cyber Security Specialist

Location
West of England, England, United Kingdom
government). Knowledge of secure system integration and API security. Strong working knowledge of SOC processes and SIEM engineering, preferably using Microsoft Sentinel (KQL, analytics rule tuning, workbooks, automation) and Microsoft Defender security tools. Understanding of supply chain security risks. SC clearance. QUALIFICATIONS & CERTIFICATIONS Degree in Cyber Security ...

Lead Platform Operations Engineer

Location
Greater London, England, United Kingdom
Networking, Security, Data) Strong hands-on experience with Kubernetes, Docker, and container orchestration Expertise in Infrastructure as Code (Terraform) and scripting (PowerShell, Bash, SQL, KQL) Proven delivery of CI/CD pipelines (Azure DevOps YAML essential) Experience implementing security tooling (SAST, DAST, container scanning, WAF) Strong knowledge of cloud security ...

Cyber Security Engineer

Location
Aberdeen City, Scotland, United Kingdom
Defender across endpoint, identity, Office 365, and cloud apps, including triage and tuning of Defender alerts. Microsoft Sentinel, including writing and tuning your own KQL queries, analytic rules, and workbooks. Microsoft Entra ID and Conditional Access policy design, testing, and troubleshooting. Microsoft Purview, Intune security controls, email security, and endpoint ...

SIEM Engineer (SC Cleared)

Location
Reading, England, United Kingdom
Microsoft Sentinel to ensure complete and reliable security telemetry Develop custom parsers and data transformations to normalise and enrich ingested data Design and optimise KQL queries to support effective threat detection and investigation Create and maintain analytic rules and detection logic aligned to emerging threats and business use cases Develop ...

SIEM Engineer (SC Cleared)

Location
Havant, England, United Kingdom
Microsoft Sentinel to ensure complete and reliable security telemetry Develop custom parsers and data transformations to normalise and enrich ingested data Design and optimise KQL queries to support effective threat detection and investigation Create and maintain analytic rules and detection logic aligned to emerging threats and business use cases Develop ...

SIEM Engineer (SC Cleared)

Hiring Organisation
Lorien
Location
Reading, Berkshire, United Kingdom
Employment Type
Full-Time
Salary
Salary negotiable
Microsoft Sentinel to ensure complete and reliable security telemetry Develop custom parsers and data transformations to normalise and enrich ingested data Design and optimise KQL queries to support effective threat detection and investigation Create and maintain analytic rules and detection logic aligned to emerging threats and business use cases Develop ...

L3 SOC Engineer - Belfast

Hiring Organisation
Lorien
Location
City, Belfast, United Kingdom
Employment Type
Permanent
Salary
GBP 60,000 Annual
Response environment Strong security monitoring and threat detection capabilities Eligibility for UK Security Clearance (SC) Experience with technologies such as Microsoft Sentinel, Microsoft Defender, KQL, QRadar, LogRhythm, SOAR platforms and other SIEM tools Strong communication and stakeholder management skills Desirable SC-200 (Microsoft Security Operations Analyst Associate) Microsoft security technology ...

2nd/3rd Line Security Analyst - Reading

Hiring Organisation
Xact Placements Limited
Location
Reading, Berkshire, United Kingdom
Employment Type
Full-Time
Salary
£50,000 - £60,000 per annum
incidents from triage through to closure Hands-on experience writing and tuning SIEM detection logic, with a solid understanding of MITRE ATT&CK and KQL (or equivalent) Practical scripting/automation experience (Python, Logic Apps, REST APIs) or hands-on SOAR platform configuration Working knowledge of several of: Microsoft Sentinel ...

Cyber Security Engineer (Threat Detection & Automation)

Hiring Organisation
Additional Resources
Location
London, United Kingdom
monitoring across cloud platforms, SaaS, and internal systems.Documenting security processes, tool configurations, and contributing to service delivery documentation.Supporting colleagues with ISO 27001 compliance and KQL-related tasks.What we are looking for:Previously worked as a Threat Detection Engineer or in a similar role.Must have strong expertise in KQL.Hands-on experience ...

Security Operations Analyst (SOC analyst)

Location
Greater London, England, United Kingdom
approximately once every five weeks). Preferred Qualifications, Capabilities, and Skills Experience with detection engineering and writing/tuning detection content (e.g., Sigma, YARA, KQL, SPL, or equivalent). Hands-on threat hunting experience using hypothesis-driven methodologies. Familiarity with SOAR platforms, scripting/automation, and AI-assisted security tooling. ...

Logs Specialist

Location
Maidenhead, England, United Kingdom
proactively provide technical guidance to unlock more log data volume and user adoption.* Conduct "Best Practice" workshops focused on log-based alerting, DQL (Dynatrace Query Language) proficiency, and dashboarding.## **What will help you succeed****Qualifications & Requirements*** Experience: 5+ years in a domain, specialist, pre-sales, professional services … role, with at least 3 years specifically focused on Log Management or Big Data analytics.* Technical Depth: Advanced proficiency in Query Languages (e.g., Splunk SPL, Kusto QL, SQL, or Lucene).* Deep understanding of Log Ingestion pipelines and "Telemetry Pipelines" (Cribl, BindPlane, Vector).* Hands-on experience with ...