1 to 25 of 42 Remote/Hybrid Kusto Query Language Jobs in England

Microsoft Security Platform Security Engineer

Location
Salford, England, United Kingdom
improvement of Microsoft Sentinel as our central security monitoring and response platform Develop and maintain detection rules, dashboards, workbooks and threat-hunting queries using KQL Create and enhance automated response playbooks using Azure Logic Apps Integrate and optimise Microsoft Defender alerts and security controls Design and implement data classification, sensitivity … Microsoft Purview Experience implementing or managing Data Loss Prevention (DLP), information protection and security monitoring solutions Proficiency in Kusto Query Language (KQL) and security analytics Experience with Azure Logic Apps, automation and Microsoft cloud security technologies Good understanding of cloud security, threat detection, incident response and cyber ...

Security Content Engineer

Location
Greater London, England, United Kingdom
expertise in a fast-paced, collaborative environment. What You'll Do: Own and Enhance Detection Content:Autonomously develop, test, andmaintainhigh-fidelity detection logic in KQL for the Microsoft Sentinel environment. You will own a portfolio of content, ensuring its long-term effectiveness and performance. Conduct Advanced Tuning & Optimization:Perform independent … creation. Deep, hands-onexpertisewith the Microsoft security stack, including Microsoft Sentinel, Microsoft 365 Defender, and Logic Apps. Highproficiencyin Kusto Query Language (KQL), with proven experience writing complex, optimized queries for detection and hunting. Strong,demonstratedexperience automating security workflowsusing SOAR platforms, APIs, or scripting languages (Python, PowerShell). ...

Cyber Security Specialist (Operational)

Location
Manchester, England, United Kingdom
description attached for full list of responsibilities. Person Specification Knowledge Knowledge of Microsoft Defender, Sentinel, including Kusto Query Language (KQL), threat hunting, analytics rule development, security monitoring, incident investigation and automation capabilities. Education/Qualifications Holds highly developed specialist knowledge and expertise acquired through master's degree ...

Cyber Security Specialist (Operational)

Hiring Organisation
NICE – The National Institute for Health and Care Excellence
Location
Manchester, M1 3BN, United Kingdom
Salary
£57528.00 to £64750.00
description attached for full list of responsibilities. Person Specification Knowledge Desirable Knowledge of Microsoft Defender, Sentinel, including Kusto Query Language (KQL), threat hunting, analytics rule development, security monitoring, incident investigation and automation capabilities. Education/Qualifications Essential Holds highly developed specialist knowledge and expertise acquired through master ...

Security Analyst: 2nd Line

Location
Newcastle upon Tyne, England, United Kingdom
Solid understanding of networking principles and security technologies, including firewalls, WAFs, application gateways and network infrastructure. Experience using Kusto Query Language (KQL) and PowerShell to investigate, automate and improve security operations. Ability to create clear technical documentation, including security playbooks, processes and network diagrams. Self-motivated ...

Automation Engineer

Hiring Organisation
Sopra Steria
Location
Farnborough, Hampshire, United Kingdom
Employment Type
Full-Time
Salary
£55,000 - £60,000 per annum
cloud-based engineering principles. It would be great if you had: Experience in Cyber Security, SOC or Security Engineering environments. Microsoft Sentinel experience. KQL, SQL or other query language knowledge. Power BI data modelling, DAX and Power Query experience. Logic Apps, Power Automate or Azure Automation. Terraform ...

Principal Microsoft Defender XDR, IRM & Deception Engineer

Hiring Organisation
Willis Towers Watson
Location
London, UK
Employment Type
Full-time
Skills & Experience: Hands-on experience with: Open-source and commercial deception/honeypot platforms (e.g., Thinkst Canary, T-Pot, Cowrie, OpenCanary, Zscaler Deception)Advanced KQL for detection engineering and threat hunting at scaleDetection-as-code, CI/CD of detection content, and security content managementStrong knowledge of adversary tradecraft ...

Lead Platform Operations Engineer

Location
Greater London, England, United Kingdom
Networking, Security, Data) Strong hands-on experience with Kubernetes, Docker, and container orchestration Expertise in Infrastructure as Code (Terraform) and scripting (PowerShell, Bash, SQL, KQL) Proven delivery of CI/CD pipelines (Azure DevOps YAML essential) Experience implementing security tooling (SAST, DAST, container scanning, WAF) Strong knowledge of cloud security ...

2nd/3rd Line Security Analyst - Reading

Hiring Organisation
Xact Placements Limited
Location
Reading, Berkshire, United Kingdom
Employment Type
Full-Time
Salary
£50,000 - £60,000 per annum
incidents from triage through to closure Hands-on experience writing and tuning SIEM detection logic, with a solid understanding of MITRE ATT&CK and KQL (or equivalent) Practical scripting/automation experience (Python, Logic Apps, REST APIs) or hands-on SOAR platform configuration Working knowledge of several of: Microsoft Sentinel ...

Logs Specialist

Location
Maidenhead, England, United Kingdom
proactively provide technical guidance to unlock more log data volume and user adoption.* Conduct "Best Practice" workshops focused on log-based alerting, DQL (Dynatrace Query Language) proficiency, and dashboarding.## **What will help you succeed****Qualifications & Requirements*** Experience: 5+ years in a domain, specialist, pre-sales, professional services … role, with at least 3 years specifically focused on Log Management or Big Data analytics.* Technical Depth: Advanced proficiency in Query Languages (e.g., Splunk SPL, Kusto QL, SQL, or Lucene).* Deep understanding of Log Ingestion pipelines and "Telemetry Pipelines" (Cribl, BindPlane, Vector).* Hands-on experience with ...

SOC Analyst

Location
Harlow, England, United Kingdom
QRadar SIEM Experience monitoring, triaging, and investigating security incidents Knowledge of incident response lifecycle and root cause analysis Experience with Microsoft Defender (essential) KQL knowledge desirable Ability to work independently and manage complex cyber investigations Technical Exposure: IBM QRadar Microsoft Defender/EDR Microsoft Sentinel (desirable) Microsoft Entra ID/ ...

SOC Analyst (MS Sentinel & Defender, SC Cleared)

Location
Harlow, England, United Kingdom
including Microsoft Sentinel Experience monitoring, triaging, and investigating security incidents Knowledge of incident response lifecycle and root cause analysis Experience with Microsoft Defender (essential) KQL knowledge desirable Ability to work independently and manage complex cyber investigations Technical Exposure: IBM QRadar Microsoft Defender/EDRMicrosoft Sentinel (essential) Microsoft Entra ID/ ...

Azure Platform Architect

Hiring Organisation
Cognitive Group | Part of the Focus Cloud Group
Location
City of London, Greater London, UK
Policy, Management Groups and subscription architecture Azure Migrate and associated discovery tooling Microsoft Defender for Cloud and Microsoft Sentinel Azure Monitor, Log Analytics and KQL Zero Trust architecture High availability and disaster recovery FinOps and cloud cost optimisation Use of GitHub Copilot to accelerate Infrastructure as Code development The Person ...

Azure Platform Architect

Location
Slough, England, United Kingdom
Policy, Management Groups and subscription architecture Azure Migrate and associated discovery tooling Microsoft Defender for Cloud and Microsoft Sentinel Azure Monitor, Log Analytics and KQL Zero Trust architecture High availability and disaster recovery FinOps and cloud cost optimisation Use of GitHub Copilot to accelerate Infrastructure as Code development The Person ...

Data Governance Managing Consultant

Location
Greater London, England, United Kingdom
Enterprise architecture frameworks (TOGAF, SABSA, or equivalent)Strong understanding of data classification models, and risk scoringAbility to design and optimise enterprise Purview deploymentsKnowledge of KQL, PowerShell, and Microsoft Graph is a plus.Capability to analyse unstructured and structured data estatesAbility to lead technical teams and influence senior leadershipAbility to work across ...

Senior Security Engineering Consultant

Hiring Organisation
Infosec
Location
Basingstoke, Hampshire, South East, United Kingdom
Employment Type
Permanent, Work From Home
Salary
£80,000
functions, tooling, and detection capabilities. Key Responsibilities: Design and deliver detection rulesets across SIEM and XDR platforms Develop and tune detection logic using KQL or equivalent query languages Design detection use cases aligned to MITRE ATT&CK and real-world attack techniques Map customer log sources to detection … Requirements: Strong hands-on experience with SIEM engineering, including developing and tuning detection rules, with Microsoft Sentinel preferred Experience writing detection logic using KQL or similar query languages Proven experience designing and implementing SOAR automations and playbooks such as Logic Apps, Cortex XSOAR or similar Scripting and automation capability ...

Senior Security Engineering Consultant

Hiring Organisation
Matchtech
Location
Basingstoke, Hampshire, UK
Employment Type
Full-time
their SOC functions, tooling, and detection capabilities. Key Responsibilities: Design and deliver detection rulesets across SIEM and XDR platformsDevelop and tune detection logic using KQL or equivalent query languagesDesign detection use cases aligned to MITRE ATT&CK and real-world attack techniquesMap customer log sources to detection use cases … detection outcomesJob Requirements: Strong hands-on experience with SIEM engineering, including developing and tuning detection rules, with Microsoft Sentinel preferredExperience writing detection logic using KQL or similar query languagesProven experience designing and implementing SOAR automations and playbooks such as Logic Apps, Cortex XSOAR or similarScripting and automation capability using ...

IT Security Analyst

Location
Derby, Derbyshire, United Kingdom
incident response should actually work in practice. From a technical angle, it would be ideal if you ve had some exposure to things like KQL, PowerShell, or similar - nothing too niche, just enough to show you can dig into data and automate where it makes sense. It would also ...

Senior Application Security Engineer / DevSecOps Engineer

Hiring Organisation
Additional Resources
Location
London, UK
Employment Type
Full-time
scale medical research. You will work closely with engineering, architecture and cloud teams to integrate security throughout the software development lifecycle. Microsoft Azure and KQL experience are essential, alongside relevant experience in CI/CD, Kubernetes, API security, security-as-code and security automation. This is a hands-on application ...

3rd Line Security Analyst

Location
Reading, England, United Kingdom
carry out malware analysis and threat validation. Design, implement and optimise detection content across Microsoft Sentinel, Defender XDR, CrowdStrike and associated platforms, developing advanced KQL queries and analytics rules aligned to MITRE ATT&CK. Act as senior technical owner for security platforms including Microsoft Sentinel, Defender XDR, CrowdStrike Falcon, Entra … Microsoft Defender XDR, CrowdStrike Falcon and associated security technologies. Proven experience in incident response, threat hunting, malware analysis, digital forensics and security investigations. Advanced KQL skills, with the ability to develop and optimise complex detections and threat hunting queries. Strong scripting and automation experience using PowerShell and/or Python ...

SC-Cleared SIEM Engineer — Microsoft Sentinel Expert

Location
Reading, England, United Kingdom
specialist SIEM Engineer with active SC clearance to enhance and automate its Microsoft Sentinel platform. You will onboard log sources, build parsers, optimise KQL queries and design detection logic. The role involves developing Logic Apps/Playbooks and setting up CI/CD pipelines for secure deployments across environments. ...

Security Analyst

Location
Greater London, England, United Kingdom
Required Proven experience in Security Operations or Cyber Security. Hands‐on experience with Splunk, log forwarding and SIEM administration. Strong analytical skills using SPL, KQL and/or SQL. Experience investigating security incidents, insider threats or data exfiltration. Knowledge of vulnerability management and security assurance within enterprise environments. #J ...

Senior Detection & Threat Engineer

Hiring Organisation
Checkout.com
Location
London, UK
Employment Type
Full-time
intrusion techniques across the attack lifecycleHands-on experience buidling detection logic in modern SIEM platforms (e.g Sentinel)Proficienty with scripting and programmaining (e.g. Python, KQL) to build detection pipelines and automationWillingness to challenge bad detections, weak assumptions, and vanity metricsPragmatic mindset: precision and impact beat coverage theatreExperience operating beyond traditional ...

24/7 SOC Analyst

Location
Basingstoke, England, United Kingdom
Experience with Microsoft Sentinel, Google SecOps or other SIEM platforms. Experience with Defender, CrowdStrike, SentinelOne or other XDR solutions. Ability to query in KQL, CQL, S1QL, XQL or similar languages. Awareness of threat intelligence concepts and application to investigations. Awareness of coding or scripting, with proficiency in at least … language preferred (but not required). Job Specifics Location: This role is home‐based with occasional visits to the office in Basingstoke Hours: 12‐hour shifts: 2 days, 2 nights; 4 days/nights off. Flexibility with hours will be required in the event of a major incident Security ...

Cyber Operations Security Engineer

Hiring Organisation
Softcat
Location
Manchester, UK
Employment Type
Full-time
efficiency across the platforms in use and surrounding technical practicesDeliver end‐to‐end SIEM/Sentinel engineering by onboarding customers, configuring data connectors, integrations, KQL, automation, dashboards and reporting. Implement tuning, enrichment and optimisation across Sentinel and align with other SIEM tools. Maintain SIEM ingestion pipeline reliability by investigating ...