1 to 25 of 75 Permanent Kusto Query Language Jobs in the UK excluding London

Senior Security SME – Microsoft Stack

Hiring Organisation
Tata Consultancy Services
Location
Manchester, England, United Kingdom
incident response .Correlate multi-source telemetry (network, endpoint, identity, cloud) to identify and contain threats. Threat Hunting & Detection Engineering: Perform proactive threat hunting using KQL within Microsoft Sentinel. Develop and fine-tune custom analytics rules, workbooks, and hunting queries. - Apply the MITRE ATT&CK framework to build coverage and improve … science, Cybersecurity, Engineering, or a related field. Hands-on experience in cybersecurity operations. Experience with Microsoft Sentinel and Microsoft Defender suite. Strong skills in KQL (Kusto Query Language) and Security architecture and data integration, Azure and Microsoft 365 security services Experience in onboarding and managing log sources ...

Senior Azure Support Engineer

Hiring Organisation
BOSS Professional Services LTD
Location
Richmond, Surrey, England, United Kingdom
Employment Type
Full-Time
Salary
£75,000 - £85,000 per annum
supporting C#/.NET Core/MVC web applications with SQL Server backends and Azure Blob Storage. Advanced Azure diagnostics (Application Insights, Log Analytics, Kusto Query Language). Proficient in SQL for investigation and remediation. Scripting and automation skills in PowerShell and/or C#. Understanding … Blob Storage, scaling strategies. Experience in capacity planning, SLOs, and error budget management Azure Monitor, Application Insights, Log Analytics, Azure Data Explorer (KQL), Azure Functions, Logic Apps, PowerShell, C#, SQL Server Management Studio, Azure Storage Explorer, Power BI (for reporting). The Senior Azure Support Engineer responsibilities and tasks: Monitor ...

Senior Security Engineer

Hiring Organisation
Cloud People
Location
Portsmouth, England, United Kingdom
Sentinel, Splunk, Defender, CrowdStrike or Elastic • Proven ability to build and tune detection rules, dashboards and automation playbooks • Knowledge of scripting or automation using KQL, PowerShell, Python or similar • Familiarity with log management, APIs and data normalisation • Understanding of cloud security across Azure, AWS and M365 • Strong grasp of network ...

Microsoft Cloud Security Architect Lead

Hiring Organisation
WTW
Location
London, South East, England, United Kingdom
Employment Type
Full-Time
Salary
Competitive salary
Automation & Integration : Using Sentinel Graph, Microsoft Graph Security API, playbooks, Logic Apps, Power Automate. Threat Management : SIEM for detection, response, hunting; SOAR workflow design; KQL queries, custom rules, UEBA. Identity & Access Security : Entra ID, Conditional Access, Identity Protection, PIM. Email Security : Microsoft Defender for O365, Darktrace AI, anti-phishing, Safe ...

SOC Analyst - Level 3

Hiring Organisation
Hyperloop Recruitment
Location
Wirral, Merseyside, North West, United Kingdom
Employment Type
Permanent
roles (MSSP experience advantageous). Advanced expertise with: CrowdStrike Falcon EDR (RTR, Forensics, Custom IOA, Identity Protection) LogScale/Next-Gen SIEM (AQL/KQL queries, dashboards, pipelines) SIEM technologies and EDR/MDR workflows in 24×7 security operations Strong automation and scripting skills (Python, PowerShell, Bash). Proficiency ...

Senior Information Security Analyst

Hiring Organisation
Pearson Whiffin Recruitment Ltd
Location
Maidstone, Kent, England, United Kingdom
Employment Type
Full-Time
Salary
£60,000 - £65,000 per annum
with Azure Security Centre, Azure AD, Defender for Cloud, and cloud security architecture. Proven expertise in Microsoft Sentinel SIEM administration, threat detection, and automation (KQL experience desirable). Solid understanding of vulnerability management with Tenable (Tenable.io/Tenable.sc). Knowledge of industry security frameworks (ISO 27001, NIST, CIS). Strong ...

Senior Information Security Analyst

Hiring Organisation
Pearson Whiffin Recruitment Ltd
Location
Maidstone, West Malling, Kent, United Kingdom
Employment Type
Permanent
Salary
£60000 - £65000/annum
with Azure Security Centre, Azure AD, Defender for Cloud, and cloud security architecture. Proven expertise in Microsoft Sentinel SIEM administration, threat detection, and automation (KQL experience desirable). Solid understanding of vulnerability management with Tenable (Tenable.io/Tenable.sc). Knowledge of industry security frameworks (ISO 27001, NIST, CIS). Strong ...

Senior Information Security Analyst

Hiring Organisation
Pearson Whiffin IT & Digital
Location
West Malling, Kent, South East, United Kingdom
Employment Type
Permanent
Salary
£65,000
with Azure Security Centre, Azure AD, Defender for Cloud, and cloud security architecture. Proven expertise in Microsoft Sentinel SIEM administration, threat detection, and automation (KQL experience desirable). Solid understanding of vulnerability management with Tenable (Tenable.io/Tenable.sc). Knowledge of industry security frameworks (ISO 27001, NIST, CIS). Strong ...

NMC Cyber Trend Analyst

Hiring Organisation
Police Digital Services
Location
Wigan, Greater Manchester, North West, United Kingdom
Employment Type
Permanent, Work From Home
starting with PDS.? Desirable Experience? . Understanding of threat landscapes, attack vectors, and adversary tactics (MITRE ATT&CK framework). Proficiency in SQL/KQL and Resource Graph for data scripting, transformation and automation. Familiarity with Azure and Fabric, using dataflows and data lakes to build scalable datasets. Understanding ...

Security Engineer

Hiring Organisation
La Fosse
Location
Buckinghamshire, UK
Employment Type
Full-time
Azure servers (P2), with a focus on advanced threat detection and automated response. Skilled in Microsoft Sentinel SIEM/SOAR setup, tuning, and KQL query development for detection engineering and incident investigation. PowerShell/Python scripting for automating Microsoft security tooling, plus experience securing DNS, DKIM/DMARC ...

Security Engineer

Hiring Organisation
La Fosse
Location
Milton Keynes, Buckinghamshire, UK
Employment Type
Full-time
Azure servers (P2), with a focus on advanced threat detection and automated response. Skilled in Microsoft Sentinel SIEM/SOAR setup, tuning, and KQL query development for detection engineering and incident investigation. PowerShell/Python scripting for automating Microsoft security tooling, plus experience securing DNS, DKIM/DMARC ...

Senior Security Engineer

Hiring Organisation
Quorum Network Resources
Location
Edinburgh, Midlothian, Scotland, United Kingdom
Employment Type
Permanent
cyber security, ideally within a Managed Service Provider Deep experience with Microsoft Defender suite (MDE, MDO, MDCA, MDI) and Microsoft Sentinel Strong knowledge of KQL, Logic Apps, and automation/orchestration tools Skilled in endpoint, identity, and cloud security Familiar with Microsoft 365 and Azure security best practices Excellent communicator ...

Senior Security Engineer

Hiring Organisation
Quorum Network Resources
Location
Edinburgh, Roxburgh's Court, City of Edinburgh, United Kingdom
Employment Type
Permanent
cyber security, ideally within a Managed Service Provider Deep experience with Microsoft Defender suite (MDE, MDO, MDCA, MDI) and Microsoft Sentinel Strong knowledge of KQL, Logic Apps, and automation/orchestration tools Skilled in endpoint, identity, and cloud security Familiar with Microsoft 365 and Azure security best practices Excellent communicator ...

Microsoft Security Engineer

Hiring Organisation
Big Red Recruitment
Location
London, South East, England, United Kingdom
Employment Type
Full-Time
Salary
Salary negotiable
deploy Microsoft Purview (DLP, classification, compliance) Implement the Defender suite (Endpoint, Identity, Cloud Apps, Office 365) Build and tune Sentinel SIEM: analytics rules, playbooks, KQL, automation Design Zero Trust controls via Entra ID: Conditional Access, PIM, RBAC Lead client-facing workshops and contribute to presales and security strategy Create LLDs ...

SIEM Engineer

Hiring Organisation
Sopra Steria
Location
Hemel Hempstead, Hertfordshire, England, United Kingdom
Employment Type
Full-Time
Salary
£65,000 - £80,000 per annum
ability to design, test and optimise detection content, including MITRE ATT&CK-aligned rules and risk-based alerting (RBA). Advanced knowledge of SPL, KQL and EQL, focused on detection quality and noise reduction. Experience with automation and Infrastructure-as-Code in SIEM environments. Deep understanding of SIEM platform operations ...

M365 Purview Compliance Design Architect

Hiring Organisation
Vallum Associates
Location
Sheffield, England, United Kingdom
performance, tenant‐wide scoping, differential targeting by region/legal entity. Automate via PowerShell/Graph, and instrument telemetry/alerting (e.g., Sentinel/KQL, compliance portals). Define controls, evidence artefacts, and reporting for internal audit and regulatory assurance. Create runbooks for policy changes, exceptions, break‐glass procedures ...

M365 Purview Compliance Design Architect

Hiring Organisation
Whitehall Resources
Location
Sheffield, England, United Kingdom
performance, tenant‐wide scoping, differential targeting by region/legal entity. * Automate via PowerShell/Graph, and instrument telemetry/alerting (e.g., Sentinel/KQL, compliance portals). * Define controls, evidence artefacts, and reporting for internal audit and regulatory assurance. * Create runbooks for policy changes, exceptions, break‐glass procedures ...

SOC Analyst

Hiring Organisation
Tria
Location
South West, United Kingdom
Employment Type
Permanent
Salary
£45000/annum
doing As SOC Analyst, you will: Operate, tune and configure SIEM tools Monitor and triage security alerts, applying custom queries (e.g. KQL) and correlation rules to detect suspicious activity. Investigate security incidents across endpoints, networks, and cloud environments; perform root-cause analysis, impact assessment and containment actions. Develop and maintain … hands-on experience with SIEM tooling, alerts triage, detection logic, and security incident workflows. Ability to write and optimise detection queries (e.g. in KQL), review firewall and security logs, manage email/web filtering policies, and implement/review Data Loss Prevention (DLP) controls. Experience with automation or scripting (e.g. ...

Security Operations Center Analyst

Hiring Organisation
TRIA
Location
Newport, UK
Employment Type
Full-time
bonus, not a requirement. What you'll be doing: Operate, tune and configure SIEM tools Monitor and triage security alerts, applying custom queries (e.g. KQL) and correlation rules to detect suspicious activity. Investigate security incidents across endpoints, networks, and cloud environments; perform root-cause analysis, impact assessment and containment actions. … hands-on experience with SIEM tooling, alerts triage, detection logic, and security incident workflows. Ability to write and optimise detection queries (e.g. in KQL), review firewall and security logs, manage email/web filtering policies, and implement/review Data Loss Prevention (DLP) controls. Experience with automation or scripting (e.g. ...

Security Operations Center Analyst

Hiring Organisation
TRIA
Location
Bath, Somerset, UK
Employment Type
Full-time
bonus, not a requirement. What you'll be doing: Operate, tune and configure SIEM tools Monitor and triage security alerts, applying custom queries (e.g. KQL) and correlation rules to detect suspicious activity. Investigate security incidents across endpoints, networks, and cloud environments; perform root-cause analysis, impact assessment and containment actions. … hands-on experience with SIEM tooling, alerts triage, detection logic, and security incident workflows. Ability to write and optimise detection queries (e.g. in KQL), review firewall and security logs, manage email/web filtering policies, and implement/review Data Loss Prevention (DLP) controls. Experience with automation or scripting (e.g. ...

Security Operations Center Analyst

Hiring Organisation
TRIA
Location
Greater Bristol Area, United Kingdom
bonus, not a requirement. What you’ll be doing: Operate, tune and configure SIEM tools Monitor and triage security alerts, applying custom queries (e.g. KQL) and correlation rules to detect suspicious activity. Investigate security incidents across endpoints, networks, and cloud environments; perform root-cause analysis, impact assessment and containment actions. … hands-on experience with SIEM tooling, alerts triage, detection logic, and security incident workflows. Ability to write and optimise detection queries (e.g. in KQL), review firewall and security logs, manage email/web filtering policies, and implement/review Data Loss Prevention (DLP) controls. Experience with automation or scripting (e.g. ...

Security Operations Center Analyst

Hiring Organisation
TRIA
Location
Bradley Stoke, Gloucestershire, UK
Employment Type
Full-time
bonus, not a requirement. What you'll be doing: Operate, tune and configure SIEM tools Monitor and triage security alerts, applying custom queries (e.g. KQL) and correlation rules to detect suspicious activity. Investigate security incidents across endpoints, networks, and cloud environments; perform root-cause analysis, impact assessment and containment actions. … hands-on experience with SIEM tooling, alerts triage, detection logic, and security incident workflows. Ability to write and optimise detection queries (e.g. in KQL), review firewall and security logs, manage email/web filtering policies, and implement/review Data Loss Prevention (DLP) controls. Experience with automation or scripting (e.g. ...

Senior Security Analyst

Hiring Organisation
SGN
Location
Glasgow, Lanarkshire, Scotland, United Kingdom
Employment Type
Full-Time
Salary
Competitive salary
junior analysts Handle complex threats, lead incident response, and shape security policy Oversee and lead investigations across various cloud security suites Develop and maintain KQL-based detection rules, hunting queries, and alert tuning strategies. Coordinate incident response playbooks across hybrid environments, including AWS EC2, Lambda, and containerized workloads. Contribute … response roles, with strong hands-on experience in Microsoft security suite, AWS Security Services, and other EDR/XDR/CNAPP platforms Proficient in KQL, PowerShell, and Python for automation and enrichment. Experience with AWS IAM, GuardDuty, Security Hub, CloudTrail, and Config. Strong understanding of UK compliance frameworks (NCSC ...

Senior SOC Engineer

Hiring Organisation
Claranet
Location
Leeds, England, United Kingdom
including data connector onboarding, ingestion optimisation, analytic rule lifecycle management, workspace architecture, and cost-aware service design for multi-tenant MSSP use cases Advanced KQL (Engineering & Detection Enablement) Expert-level KQL skills to support detection engineering, correlation logic, operational tuning, and platform performance across Sentinel and Defender data sources SOAR ...

Sentinel Deployment Engineer

Hiring Organisation
Hamilton Barnes
Location
Aberdeen, UK
Employment Type
Full-time
Will Ideally Bring: Strong experience with Azure Cloud technologies, Microsoft Sentinel and Defender solution. Experience in query languages and/or script development (KQL, SPL, SQL, Powershell, etc.) Knowledge and familiarity of enterprise IT systems in relation to cyber security. Hands-on engineering experience with SIEM and/ ...