1 to 25 of 90 Permanent Kusto Query Language Jobs

Security Engineer – Cloud & On-Prem (Hybrid Security)

Location
Greater London, England, United Kingdom
repetitive security activities and operational processes. Use PowerShell and other scripting technologies to support security administration and investigation. Develop skills across Microsoft Graph API, KQL, Azure CLI, Logic Apps and security automation. Support the development of Sentinel automation rules and playbooks. Contribute to improving security monitoring, detection and response processes. … cloud and hybrid security. Desirable Experience Experience in any of the following would be advantageous: Microsoft Sentinel and Kusto Query Language (KQL). Microsoft Defender XDR, Defender for Endpoint or Defender for Identity. Microsoft Defender for Cloud and Cloud Security Posture Management. Entra ID security, including Conditional ...

Security Content Engineer

Location
Greater London, England, United Kingdom
expertise in a fast-paced, collaborative environment. What You'll Do: Own and Enhance Detection Content:Autonomously develop, test, andmaintainhigh-fidelity detection logic in KQL for the Microsoft Sentinel environment. You will own a portfolio of content, ensuring its long-term effectiveness and performance. Conduct Advanced Tuning & Optimization:Perform independent … creation. Deep, hands-onexpertisewith the Microsoft security stack, including Microsoft Sentinel, Microsoft 365 Defender, and Logic Apps. Highproficiencyin Kusto Query Language (KQL), with proven experience writing complex, optimized queries for detection and hunting. Strong,demonstratedexperience automating security workflowsusing SOAR platforms, APIs, or scripting languages (Python, PowerShell). ...

24 x 7 Security Analyst

Location
Birmingham, England, United Kingdom
enhance visibility, resilience, and incident response effectiveness. Experience in conducting security investigations using large datasets , with knowledge of Kusto Query Language (KQL) to develop custom Sentinel queries and analytics rules. Solid understanding of enterprise IT infrastructure , including Windows and Linux operating systems, networking, and third‐party security ...

Senior Software Engineer

Location
Greater London, England, United Kingdom
XMLA endpoints for managing semantic models programmatically Databricks - Delta Lake and SQL warehouses, where our cost and usage data is processed, modelled and served KQL (Kusto Query Language) - querying Azure Monitor, Log Analytics and resource telemetry Azure - Cost Management and Billing, Advisor, Azure Policy and Monitor, plus ...

Security Analyst: 2nd Line

Location
Newcastle upon Tyne, England, United Kingdom
Solid understanding of networking principles and security technologies, including firewalls, WAFs, application gateways and network infrastructure. Experience using Kusto Query Language (KQL) and PowerShell to investigate, automate and improve security operations. Ability to create clear technical documentation, including security playbooks, processes and network diagrams. Self-motivated ...

Managing Engineer - Observability, Pipeline & Analytics (Hybrid)

Location
Belfast City District, Northern Ireland, United Kingdom
transformation initiatives. Desirable Skills: Experience implementing telemetry cost optimization and data reduction strategies at enterprise scale. Knowledge of Kusto Query Language (KQL) and large‐scale analytics platforms. Experience with Cribl, ADX, Datadog Pipelines, Splunk, Sentinel, Kafka, Event Hubs, Open Telemetry, Elastic, Grafana, or similar observability ecosystems. Ability ...

Senior Cyber Threat Intelligence (CTI) Analyst

Location
United Kingdom
attacker tooling using sandbox or detonation environments and extracting IOCs, C2 infrastructure, and behavioral indicators.Proficiency in at least one query language (KQL, SPL, CQL, SQL), the ability to read and understand code, and working scripting ability (e.g., Python, Bash) for enrichment and automation.Strong written and verbal communication skills ...

Senior Cyber Threat Intelligence (CTI) Analyst

Location
Greater London, England, United Kingdom
attacker tooling using sandbox or detonation environments and extracting IOCs, C2 infrastructure, and behavioural indicators. Proficiency in at least one query language (KQL, SPL, CQL, SQL), the ability to read and understand code, and working scripting ability (e.g., Python, Bash) for enrichment and automation. Strong written and verbal ...

Senior Microsoft Security Engineer (XDR, IRM, Deception Engineering)

Location
Greater London, England, United Kingdom
Skills & Experience: Hands‐on experience with: Open‐source and commercial deception/honeypot platforms (e.g., Thinkst Canary, T‐Pot, Cowrie, OpenCanary, Zscaler Deception) Advanced KQL for detection engineering and threat hunting at scale Detection‐as‐code, CI/CD of detection content, and security content management Strong knowledge of adversary ...

Principal Microsoft Defender XDR, IRM & Deception Engineer

Hiring Organisation
Willis Towers Watson
Location
London, UK
Employment Type
Full-time
Skills & Experience: Hands-on experience with: Open-source and commercial deception/honeypot platforms (e.g., Thinkst Canary, T-Pot, Cowrie, OpenCanary, Zscaler Deception)Advanced KQL for detection engineering and threat hunting at scaleDetection-as-code, CI/CD of detection content, and security content managementStrong knowledge of adversary tradecraft ...

Senior Microsoft Identity Security Specialist

Location
Greater London, England, United Kingdom
translate architecture and security standards into practical engineering solutions. Strong communication, documentation and stakeholder-engagement skills. Desirable Experience: Microsoft Sentinel, Log Analytics/KQL, Defender for Identity, Defender for Cloud Apps or Copilot for Security. Microsoft Graph, Python, Logic Apps, Azure Functions, policy-as-code, infrastructure-as-code or advanced ...

Technical Analyst

Location
United Kingdom
cataloguing and lineage use cases. Skills & Competencies Ability to configure and manage Purview policies and scanning tools. Strong analytical and troubleshooting skills. Familiarity with KQL, PowerShell, or Microsoft Graph. Ability to interpret logs, alerts, and governance reporting. Strong documentation and verbal communication skills. Ability to work collaboratively with cross functional ...

Level 3 SOC Analyst

Location
Belfast City District, Northern Ireland, United Kingdom
platforms, including IBM QRadar, Microsoft Sentinel and LogRhythm In-depth experience with Microsoft Sentinel, including use case and rule development, workbook/playbook creation, KQL & Logic Apps/SOAR Experience in managing Microsoft Sentinel as an MSSP, including Lighthouse, and management and multi-customer environments using DevOps How this aligns ...

SIEM Engineer (SC Cleared)

Hiring Organisation
Lorien
Location
Reading, Berkshire, United Kingdom
Employment Type
Full-Time
Salary
Salary negotiable
Microsoft Sentinel to ensure complete and reliable security telemetry Develop custom parsers and data transformations to normalise and enrich ingested data Design and optimise KQL queries to support effective threat detection and investigation Create and maintain analytic rules and detection logic aligned to emerging threats and business use cases Develop ...

Lead Platform Operations Engineer

Location
Greater London, England, United Kingdom
Networking, Security, Data) Strong hands-on experience with Kubernetes, Docker, and container orchestration Expertise in Infrastructure as Code (Terraform) and scripting (PowerShell, Bash, SQL, KQL) Proven delivery of CI/CD pipelines (Azure DevOps YAML essential) Experience implementing security tooling (SAST, DAST, container scanning, WAF) Strong knowledge of cloud security ...

Manager - Cyber Security Specialist

Location
West of England, England, United Kingdom
government). Knowledge of secure system integration and API security. Strong working knowledge of SOC processes and SIEM engineering, preferably using Microsoft Sentinel (KQL, analytics rule tuning, workbooks, automation) and Microsoft Defender security tools. Understanding of supply chain security risks. SC clearance. QUALIFICATIONS & CERTIFICATIONS Degree in Cyber Security ...

2nd/3rd Line Security Analyst - Reading

Hiring Organisation
Xact Placements Limited
Location
Reading, Berkshire, United Kingdom
Employment Type
Full-Time
Salary
£50,000 - £60,000 per annum
incidents from triage through to closure Hands-on experience writing and tuning SIEM detection logic, with a solid understanding of MITRE ATT&CK and KQL (or equivalent) Practical scripting/automation experience (Python, Logic Apps, REST APIs) or hands-on SOAR platform configuration Working knowledge of several of: Microsoft Sentinel ...

Cyber Security Engineer

Location
Aberdeen City, Scotland, United Kingdom
Defender across endpoint, identity, Office 365, and cloud apps, including triage and tuning of Defender alerts. Microsoft Sentinel, including writing and tuning your own KQL queries, analytic rules, and workbooks. Microsoft Entra ID and Conditional Access policy design, testing, and troubleshooting. Microsoft Purview, Intune security controls, email security, and endpoint ...

3rd Line Security Analyst - Hybrid - Reading Sentinel Defender XDR CrowdStrike

Hiring Organisation
Global Technology Solutions Ltd
Location
Reading, Berkshire, South East, United Kingdom
Employment Type
Permanent
Salary
£60,000
cyber operations or security engineering experience. Hands-on Sentinel, Defender XDR and CrowdStrike expertise. Incident response, malware analysis, forensics and threat hunting. Advanced KQL; PowerShell and/or Python automation. Entra ID, Conditional Access, Intune and Microsoft 365 security. Cloud and networking knowledge; MITRE ATT&CK, NIST and SANS frameworks. ...

SOC Analyst (MS Sentinel & Defender, SC Cleared)

Location
Harlow, England, United Kingdom
including Microsoft Sentinel Experience monitoring, triaging, and investigating security incidents Knowledge of incident response lifecycle and root cause analysis Experience with Microsoft Defender (essential) KQL knowledge desirable Ability to work independently and manage complex cyber investigations Technical Exposure: IBM QRadar Microsoft Defender/EDRMicrosoft Sentinel (essential) Microsoft Entra ID/ ...

Cyber Security Engineer (Threat Detection & Automation)

Hiring Organisation
Additional Resources
Location
London, UK
Employment Type
Full-time
cloud platforms, SaaS, and internal systems. Documenting security processes, tool configurations, and contributing to service delivery documentation. Supporting colleagues with ISO 27001 compliance and KQL-related tasks. What we are looking for: Previously worked as a Threat Detection Engineer or in a similar role. Must have strong expertise in KQL.Hands ...

Security Operations Analyst (SOC analyst)

Location
Greater London, England, United Kingdom
approximately once every five weeks). Preferred Qualifications, Capabilities, and Skills Experience with detection engineering and writing/tuning detection content (e.g., Sigma, YARA, KQL, SPL, or equivalent). Hands-on threat hunting experience using hypothesis-driven methodologies. Familiarity with SOAR platforms, scripting/automation, and AI-assisted security tooling. ...

SC-Cleared SIEM Engineer: Sentinel & SOAR Automation

Location
Reading, England, United Kingdom
onboard and integrate security log sources into Microsoft Sentinel, delivering reliable telemetry and comprehensive threat visibility. You will develop custom parsers, transformations and KQL queries, and design SIEM detections aligned to evolving threats. CI/CD pipelines with Azure DevOps/Git enable controlled deployments. #J-18808-Ljbffr ...

Security engineer

Hiring Organisation
Tria
Location
Cardiff, South Glamorgan, United Kingdom
Employment Type
Permanent
Salary
£45000 - £50000/annum
participate in an on-call rota. What we're looking for Strong hands-on experience with Microsoft Defender XDR and Sentinel. Very good KQL and Advanced Hunting skills. Practical experience building, configuring or improving security solutions. Familiarity with DevOps and CI/CD pipelines. Confidence communicating with clients and explaining ...

Azure Platform Architect

Location
Slough, England, United Kingdom
Policy, Management Groups and subscription architecture Azure Migrate and associated discovery tooling Microsoft Defender for Cloud and Microsoft Sentinel Azure Monitor, Log Analytics and KQL Zero Trust architecture High availability and disaster recovery FinOps and cloud cost optimisation Use of GitHub Copilot to accelerate Infrastructure as Code development The Person ...