1 to 25 of 45 Remote/Hybrid Permanent Kusto Query Language Jobs

Security Engineer – Cloud & On-Prem (Hybrid Security)

Location
Greater London, England, United Kingdom
repetitive security activities and operational processes. Use PowerShell and other scripting technologies to support security administration and investigation. Develop skills across Microsoft Graph API, KQL, Azure CLI, Logic Apps and security automation. Support the development of Sentinel automation rules and playbooks. Contribute to improving security monitoring, detection and response processes. … cloud and hybrid security. Desirable Experience Experience in any of the following would be advantageous: Microsoft Sentinel and Kusto Query Language (KQL). Microsoft Defender XDR, Defender for Endpoint or Defender for Identity. Microsoft Defender for Cloud and Cloud Security Posture Management. Entra ID security, including Conditional ...

Security Content Engineer

Location
Greater London, England, United Kingdom
expertise in a fast-paced, collaborative environment. What You'll Do: Own and Enhance Detection Content:Autonomously develop, test, andmaintainhigh-fidelity detection logic in KQL for the Microsoft Sentinel environment. You will own a portfolio of content, ensuring its long-term effectiveness and performance. Conduct Advanced Tuning & Optimization:Perform independent … creation. Deep, hands-onexpertisewith the Microsoft security stack, including Microsoft Sentinel, Microsoft 365 Defender, and Logic Apps. Highproficiencyin Kusto Query Language (KQL), with proven experience writing complex, optimized queries for detection and hunting. Strong,demonstratedexperience automating security workflowsusing SOAR platforms, APIs, or scripting languages (Python, PowerShell). ...

Security Analyst: 2nd Line

Location
Newcastle upon Tyne, England, United Kingdom
Solid understanding of networking principles and security technologies, including firewalls, WAFs, application gateways and network infrastructure. Experience using Kusto Query Language (KQL) and PowerShell to investigate, automate and improve security operations. Ability to create clear technical documentation, including security playbooks, processes and network diagrams. Self-motivated ...

Managing Engineer - Observability, Pipeline & Analytics (Hybrid)

Location
Belfast City District, Northern Ireland, United Kingdom
transformation initiatives. Desirable Skills: Experience implementing telemetry cost optimization and data reduction strategies at enterprise scale. Knowledge of Kusto Query Language (KQL) and large‐scale analytics platforms. Experience with Cribl, ADX, Datadog Pipelines, Splunk, Sentinel, Kafka, Event Hubs, Open Telemetry, Elastic, Grafana, or similar observability ecosystems. Ability ...

Senior Microsoft Security Engineer (XDR, IRM, Deception Engineering)

Location
Greater London, England, United Kingdom
Skills & Experience: Hands‐on experience with: Open‐source and commercial deception/honeypot platforms (e.g., Thinkst Canary, T‐Pot, Cowrie, OpenCanary, Zscaler Deception) Advanced KQL for detection engineering and threat hunting at scale Detection‐as‐code, CI/CD of detection content, and security content management Strong knowledge of adversary ...

Principal Microsoft Defender XDR, IRM & Deception Engineer

Hiring Organisation
Willis Towers Watson
Location
London, UK
Employment Type
Full-time
Skills & Experience: Hands-on experience with: Open-source and commercial deception/honeypot platforms (e.g., Thinkst Canary, T-Pot, Cowrie, OpenCanary, Zscaler Deception)Advanced KQL for detection engineering and threat hunting at scaleDetection-as-code, CI/CD of detection content, and security content managementStrong knowledge of adversary tradecraft ...

Senior Microsoft Identity Security Specialist

Location
Greater London, England, United Kingdom
translate architecture and security standards into practical engineering solutions. Strong communication, documentation and stakeholder-engagement skills. Desirable Experience: Microsoft Sentinel, Log Analytics/KQL, Defender for Identity, Defender for Cloud Apps or Copilot for Security. Microsoft Graph, Python, Logic Apps, Azure Functions, policy-as-code, infrastructure-as-code or advanced ...

Technical Analyst

Location
United Kingdom
cataloguing and lineage use cases. Skills & Competencies Ability to configure and manage Purview policies and scanning tools. Strong analytical and troubleshooting skills. Familiarity with KQL, PowerShell, or Microsoft Graph. Ability to interpret logs, alerts, and governance reporting. Strong documentation and verbal communication skills. Ability to work collaboratively with cross functional ...

Lead Platform Operations Engineer

Location
Greater London, England, United Kingdom
Networking, Security, Data) Strong hands-on experience with Kubernetes, Docker, and container orchestration Expertise in Infrastructure as Code (Terraform) and scripting (PowerShell, Bash, SQL, KQL) Proven delivery of CI/CD pipelines (Azure DevOps YAML essential) Experience implementing security tooling (SAST, DAST, container scanning, WAF) Strong knowledge of cloud security ...

2nd/3rd Line Security Analyst - Reading

Hiring Organisation
Xact Placements Limited
Location
Reading, Berkshire, United Kingdom
Employment Type
Full-Time
Salary
£50,000 - £60,000 per annum
incidents from triage through to closure Hands-on experience writing and tuning SIEM detection logic, with a solid understanding of MITRE ATT&CK and KQL (or equivalent) Practical scripting/automation experience (Python, Logic Apps, REST APIs) or hands-on SOAR platform configuration Working knowledge of several of: Microsoft Sentinel ...

3rd Line Security Analyst - Hybrid - Reading Sentinel Defender XDR CrowdStrike

Hiring Organisation
Global Technology Solutions Ltd
Location
Reading, Berkshire, South East, United Kingdom
Employment Type
Permanent
Salary
£60,000
cyber operations or security engineering experience. Hands-on Sentinel, Defender XDR and CrowdStrike expertise. Incident response, malware analysis, forensics and threat hunting. Advanced KQL; PowerShell and/or Python automation. Entra ID, Conditional Access, Intune and Microsoft 365 security. Cloud and networking knowledge; MITRE ATT&CK, NIST and SANS frameworks. ...

SOC Analyst (MS Sentinel & Defender, SC Cleared)

Location
Harlow, England, United Kingdom
including Microsoft Sentinel Experience monitoring, triaging, and investigating security incidents Knowledge of incident response lifecycle and root cause analysis Experience with Microsoft Defender (essential) KQL knowledge desirable Ability to work independently and manage complex cyber investigations Technical Exposure: IBM QRadar Microsoft Defender/EDRMicrosoft Sentinel (essential) Microsoft Entra ID/ ...

Cyber Security Engineer (Threat Detection & Automation)

Hiring Organisation
Additional Resources
Location
London, UK
Employment Type
Full-time
cloud platforms, SaaS, and internal systems. Documenting security processes, tool configurations, and contributing to service delivery documentation. Supporting colleagues with ISO 27001 compliance and KQL-related tasks. What we are looking for: Previously worked as a Threat Detection Engineer or in a similar role. Must have strong expertise in KQL.Hands ...

Azure Platform Architect

Location
Slough, England, United Kingdom
Policy, Management Groups and subscription architecture Azure Migrate and associated discovery tooling Microsoft Defender for Cloud and Microsoft Sentinel Azure Monitor, Log Analytics and KQL Zero Trust architecture High availability and disaster recovery FinOps and cloud cost optimisation Use of GitHub Copilot to accelerate Infrastructure as Code development The Person ...

Security Monitoring & Detection Engineering Lead

Location
Manchester, England, United Kingdom
enterprise environment. A strong record of designing, building, operating and evolving Microsoft Sentinel as a production security monitoring and response capability. Deep expertise in KQL and the engineering of analytics rules, hunting queries, workbooks and threat‐informed detection content. Extensive experience designing telemetry architectures and onboarding security data, including connectors ...

Security Monitoring & Detection Engineering Lead

Location
Greater London, England, United Kingdom
enterprise environment. A strong record of designing, building, operating and evolving Microsoft Sentinel as a production security monitoring and response capability. Deep expertise in KQL and the engineering of analytics rules, hunting queries, workbooks and threat‐informed detection content. Extensive experience designing telemetry architectures and onboarding security data, including connectors ...

Senior Security Engineering Consultant

Hiring Organisation
Matchtech
Location
Basingstoke, Hampshire, UK
Employment Type
Full-time
their SOC functions, tooling, and detection capabilities. Key Responsibilities: Design and deliver detection rulesets across SIEM and XDR platformsDevelop and tune detection logic using KQL or equivalent query languagesDesign detection use cases aligned to MITRE ATT&CK and real-world attack techniquesMap customer log sources to detection use cases … detection outcomesJob Requirements: Strong hands-on experience with SIEM engineering, including developing and tuning detection rules, with Microsoft Sentinel preferredExperience writing detection logic using KQL or similar query languagesProven experience designing and implementing SOAR automations and playbooks such as Logic Apps, Cortex XSOAR or similarScripting and automation capability using ...

Senior Security Engineering Consultant

Hiring Organisation
Infosec
Location
Basingstoke, Hampshire, South East, United Kingdom
Employment Type
Permanent, Work From Home
Salary
£80,000
functions, tooling, and detection capabilities. Key Responsibilities: Design and deliver detection rulesets across SIEM and XDR platforms Develop and tune detection logic using KQL or equivalent query languages Design detection use cases aligned to MITRE ATT&CK and real-world attack techniques Map customer log sources to detection … Requirements: Strong hands-on experience with SIEM engineering, including developing and tuning detection rules, with Microsoft Sentinel preferred Experience writing detection logic using KQL or similar query languages Proven experience designing and implementing SOAR automations and playbooks such as Logic Apps, Cortex XSOAR or similar Scripting and automation capability ...

Incident Response Engineer 2

Location
Oxford, England, United Kingdom
weekends and holidays as part of a rotation Desired: Hands-on experience with EDR, SIEM, and forensic collection tools Familiarity with OSQuery, SQL, or KQL Knowledge of MITRE ATT&CK and incident response frameworks Industry certifications such as GCIH, GCED, CompTIA Security+, or equivalent Experience contributing to playbooks, detection tuning ...

IAM Consultant/Developer (Microsoft Entra ID) - Contract role, UK, fully remote

Location
United Kingdom
identity lifecycle automation, ideally via the Microsoft Graph PowerShell SDK. Comfortable working independently and communicating migration risk/status to non-technical stakeholders. Desirable: KQL for log analysis in Microsoft Sentinel or Azure Monitor. Experience with Entra ID B2B/B2C. Background with an alternative IAM platform (ForgeRock, Ping, Okta ...

IAM Consultant/Developer (Microsoft Entra ID) - UK, fully remote

Location
Greater London, England, United Kingdom
identity lifecycle automation, ideally via the Microsoft Graph PowerShell SDK. Comfortable working independently and communicating migration risk/status to non‐technical stakeholders. Desirable: KQL for log analysis in Microsoft Sentinel or Azure Monitor. Experience with Entra ID B2B/B2C. Background with an alternative IAM platform (ForgeRock, Ping, Okta ...

Senior Cyber Security Engineer

Hiring Organisation
Checkout.com
Location
London, UK
Employment Type
Full-time
understanding of security operations workflows: alert triage, incident handling, and vulnerability/finding remediation lifecyclesComfort with scripting to support automation and tooling (e.g. Python, KQL)Experience coordinating remediation across multiple engineering or platform teams, and keeping work moving to closureWorking knowledge of cloud environments (e.g. AWS, Azure ...

Cyber Security Analyst

Hiring Organisation
XACT PLACEMENTS LIMITED
Location
Reading, Berkshire, South East, United Kingdom
Employment Type
Permanent, Work From Home
Salary
£60,000
carry out malware analysis and threat validation. Design, implement and optimise detection content across Microsoft Sentinel, Defender XDR, CrowdStrike and associated platforms, developing advanced KQL queries and analytics rules aligned to MITRE ATT&CK. Act as senior technical owner for security platforms including Microsoft Sentinel, Defender XDR, CrowdStrike Falcon, Entra … Microsoft Defender XDR, CrowdStrike Falcon and associated security technologies. Proven experience in incident response, threat hunting, malware analysis, digital forensics and security investigations. Advanced KQL skills, with the ability to develop and optimise complex detections and threat hunting queries. Strong scripting and automation experience using PowerShell and/or Python ...

3rd Line Security Analyst

Location
Reading, England, United Kingdom
carry out malware analysis and threat validation. Design, implement and optimise detection content across Microsoft Sentinel, Defender XDR, CrowdStrike and associated platforms, developing advanced KQL queries and analytics rules aligned to MITRE ATT&CK. Act as senior technical owner for security platforms including Microsoft Sentinel, Defender XDR, CrowdStrike Falcon, Entra … Microsoft Defender XDR, CrowdStrike Falcon and associated security technologies. Proven experience in incident response, threat hunting, malware analysis, digital forensics and security investigations. Advanced KQL skills, with the ability to develop and optimise complex detections and threat hunting queries. Strong scripting and automation experience using PowerShell and/or Python ...

Hybrid SecOps Engineering Lead: Azure & SOC

Location
Abingdon, England, United Kingdom
lead security operations, detections, and the three-analyst team, troubleshooting issues and guiding engineering teams. Essential experience includes security engineering/operations, Microsoft Sentinel, KQL, incident response on cloud platforms, and IaC with Terraform/Bicep. #J-18808-Ljbffr ...