1 to 25 of 38 Kusto Query Language Jobs in London

SIEM Engineer (SC Clearance required)

Location
London, United Kingdom
LogRhythm expertise Check Point knowledge Experience developing Logic Apps, Playbooks and SOAR automation workflows. Experience onboarding and integrating diverse data sources Strong knowledge of KQL (Kusto Query Language), advanced query development and optimisation. Desirable skills: SANS SEC503 - Network Monitoring and Threat Detection. Please submit your updated ...

Security Content Engineer

Location
Greater London, England, United Kingdom
expertise in a fast-paced, collaborative environment. What You'll Do: Own and Enhance Detection Content:Autonomously develop, test, andmaintainhigh-fidelity detection logic in KQL for the Microsoft Sentinel environment. You will own a portfolio of content, ensuring its long-term effectiveness and performance. Conduct Advanced Tuning & Optimization:Perform independent … creation. Deep, hands-onexpertisewith the Microsoft security stack, including Microsoft Sentinel, Microsoft 365 Defender, and Logic Apps. Highproficiencyin Kusto Query Language (KQL), with proven experience writing complex, optimized queries for detection and hunting. Strong,demonstratedexperience automating security workflowsusing SOAR platforms, APIs, or scripting languages (Python, PowerShell). ...

Exchange SME

Hiring Organisation
Morson Edge
Location
London, United Kingdom
Employment Type
Contract
Contract Rate
£400 - 440 per day
Implement security best practices, including privileged access management and least privilege. Microsoft Sentinel Deploy, configure, and manage Microsoft Sentinel. Develop and maintain analytics rules, KQL queries, workbooks, and automation. Investigate security incidents and suspicious activity. Integrate Microsoft Sentinel with Active Directory, Microsoft 365, Defender, and other security platforms. Develop Logic … Services Group Policy DNS, DHCP, TCP/IP PowerShell Microsoft 365 Microsoft Entra ID Microsoft Defender Microsoft Sentinel Kusto Query Language (KQL) Windows Server Azure Hybrid identity and Exchange environments Security monitoring and incident response Please send your CV fo immediate interview ...

Senior Cyber Threat Intelligence (CTI) Analyst

Location
Greater London, England, United Kingdom
attacker tooling using sandbox or detonation environments and extracting IOCs, C2 infrastructure, and behavioural indicators. Proficiency in at least one query language (KQL, SPL, CQL, SQL), the ability to read and understand code, and working scripting ability (e.g., Python, Bash) for enrichment and automation. Strong written and verbal ...

Senior Cyber Security Analyst

Hiring Organisation
Lightsource bp
Location
London, UK
Employment Type
Full-time
Security Operations Center (SOC) or incident response role Advanced proficiency with Microsoft Defender XDR and expert-level knowledge of Microsoft Sentinel, including KQL query writing and analytics rule development Strong hands-on experience with Microsoft Defender for Endpoint, including policy configuration and threat investigation Demonstrable experience responding to cyber ...

Threat Intelligence Analyst

Location
Greater London, England, United Kingdom
sharing platforms, and dark web monitoring tools Correlate external intelligence with internal security events using Microsoft Sentinel and Microsoft Defender Develop and maintain advanced KQL queries for threat hunting, detection engineering, and incident investigation Produce actionable threat intelligence reports, threat actor profiles, IoCs, and executive briefings Support and participate … methodologies, and intelligence frameworks such as MITRE ATT&CK, the Diamond Model, and Cyber Kill Chain Advanced knowledge of Microsoft Sentinel, Microsoft Defender, and KQL for threat hunting and investigation Experience working with threat intelligence platforms and dark web monitoring solutions, such as DarkIQ or equivalent Strong analytical skills with ...

Lead Platform Operations Engineer

Location
Greater London, England, United Kingdom
Networking, Security, Data) Strong hands-on experience with Kubernetes, Docker, and container orchestration Expertise in Infrastructure as Code (Terraform) and scripting (PowerShell, Bash, SQL, KQL) Proven delivery of CI/CD pipelines (Azure DevOps YAML essential) Experience implementing security tooling (SAST, DAST, container scanning, WAF) Strong knowledge of cloud security ...

Cyber Security Engineer (Threat Detection & Automation)

Hiring Organisation
Appcast
Location
London, UK
monitoring across cloud platforms, SaaS, and internal systems.Documenting security processes, tool configurations, and contributing to service delivery documentation.Supporting colleagues with ISO 27001 compliance and KQL-related tasks.What we are looking for:Previously worked as a Threat Detection Engineer or in a similar role.Must have strong expertise in KQL.Hands-on experience ...

Cyber Security Engineer (Threat Detection & Automation)

Hiring Organisation
Additional Resources
Location
London, UK
Employment Type
Full-time
cloud platforms, SaaS, and internal systems. Documenting security processes, tool configurations, and contributing to service delivery documentation. Supporting colleagues with ISO 27001 compliance and KQL-related tasks. What we are looking for: Previously worked as a Threat Detection Engineer or in a similar role. Must have strong expertise in KQL.Hands ...

Associate Security Analyst

Hiring Organisation
NonStop Consulting
Location
London, United Kingdom
Employment Type
Contract
Contract Rate
£650 - £700/day
Analyst. Hands-on experience with SIEM (Splunk preferred; Microsoft Sentinel or equivalent also considered). Experience with M365 security tooling (e.g. Microsoft Defender, Sentinel, KQL). Good understanding of threat actors' tools, techniques and procedures . Strong analytical, problem-solving and communication skills. Nice to have Further experience with Splunk ...

Associate Security Analyst

Hiring Organisation
NonStop Consulting Ltd
Location
London, South East England, United Kingdom
Employment Type
Full-Time
Salary
£650.00 - £700.00 per day
Analyst. Hands-on experience with SIEM (Splunk preferred; Microsoft Sentinel or equivalent also considered). Experience with M365 security tooling (e.g. Microsoft Defender, Sentinel, KQL). Good understanding of threat actors' tools, techniques and procedures . Strong analytical, problem-solving and communication skills. Nice to have Further experience with Splunk ...

Security Operations Analyst (SOC analyst)

Location
Greater London, England, United Kingdom
approximately once every five weeks). Preferred Qualifications, Capabilities, And Skills Experience with detection engineering and writing/tuning detection content (e.g., Sigma, YARA, KQL, SPL, or equivalent). Hands-on threat hunting experience using hypothesis-driven methodologies. Familiarity with SOAR platforms, scripting/automation, and AI-assisted security tooling. ...

Azure Platform Architect

Location
Greater London, England, United Kingdom
Policy, Management Groups and subscription architecture Azure Migrate and associated discovery tooling Microsoft Defender for Cloud and Microsoft Sentinel Azure Monitor, Log Analytics and KQL Zero Trust architecture High availability and disaster recovery FinOps and cloud cost optimisation Use of GitHub Copilot to accelerate Infrastructure as Code development The Person ...

Data Governance Managing Consultant

Location
Greater London, England, United Kingdom
Enterprise architecture frameworks (TOGAF, SABSA, or equivalent)Strong understanding of data classification models, and risk scoringAbility to design and optimise enterprise Purview deploymentsKnowledge of KQL, PowerShell, and Microsoft Graph is a plus.Capability to analyse unstructured and structured data estatesAbility to lead technical teams and influence senior leadershipAbility to work across ...

Lead Threat Detection Engineer

Location
Greater London, England, United Kingdom
than purely responding to SOC alerts Strong SIEM experience – Microsoft Sentinel, Splunk or similar Cloud security experience across AWS, GCP and/or Azure KQL, SPL or similar querying experience Python scripting/security automation Terraform/Infrastructure as Code exposure Experience with threat intelligence or threat hunting Strong ownership ...

security engineer in legal services

Location
Greater London, England, United Kingdom
Sentinel, Exabeam, Splunk, or equivalent Experience with vulnerability management using Tenable or equivalent enterprise toolsets Experience with scripting and automation, preferably PowerShell, and KQL or similar Experience with Data Loss Prevention solutions, including MS Purview Compliance Manager Nice to have: CISSP, CREST Practitioner Security Analyst (CPSA), Palo Alto Networks Certified ...

Senior Security Engineer - Contract

Location
Greater London, England, United Kingdom
security risk clearly to engineering and product audiences. A growth mindset and genuine curiosity to keep learning. SC-200 (Microsoft Security Operations Analyst) certification. KQL proficiency for detection rule authoring and threat hunting. Experience working in a similar fintech or financial services environment All are welcome: At Flagstone ...

Senior Security Architect - SecOps and Vulnerability Management

Hiring Organisation
JP Morgan Chase
Location
London, UK
Employment Type
Full-time
advising and influencing enterprise SIEM platforms (e.g., Microsoft Sentinel, Splunk, Chronicle/SecOps). Must be proficient in writing/reviewing advanced detection logic (KQL, SPL, or YARA rules).Deep execution knowledge of generating, managing, and analyzing Software Bills of Materials (SBOMs using frameworks like CycloneDX or SPDX) and integrating ...

Senior Security Architect - SecOps and Vulnerability Management

Hiring Organisation
Hackajob Ltd
Location
South West London, London, United Kingdom
Employment Type
Permanent
advising and influencing enterprise SIEM platforms (e.g., Microsoft Sentinel, Splunk, Chronicle/SecOps). Must be proficient in writing/reviewing advanced detection logic (KQL, SPL, or YARA rules). Deep execution knowledge of generating, managing, and analyzing Software Bills of Materials (SBOMs using frameworks like CycloneDX or SPDX ...

Senior Application Security Engineer / DevSecOps Engineer

Location
Greater London, England, United Kingdom
scale medical research. You will work closely with engineering, architecture and cloud teams to integrate security throughout the software development lifecycle. Microsoft Azure and KQL experience are essential, alongside relevant experience in CI/CD, Kubernetes, API security, security:as:code and security automation. This is a hands:on application ...

Senior Application Security Engineer / DevSecOps Engineer

Hiring Organisation
Additional Resources
Location
London, United Kingdom
Employment Type
Permanent
Salary
£80000 - £90000/annum
scale medical research. You will work closely with engineering, architecture and cloud teams to integrate security throughout the software development lifecycle. Microsoft Azure and KQL experience are essential, alongside relevant experience in CI/CD, Kubernetes, API security, security-as-code and security automation. This is a hands-on application ...

Security Analyst

Location
Greater London, England, United Kingdom
Required Proven experience in Security Operations or Cyber Security. Hands‐on experience with Splunk, log forwarding and SIEM administration. Strong analytical skills using SPL, KQL and/or SQL. Experience investigating security incidents, insider threats or data exfiltration. Knowledge of vulnerability management and security assurance within enterprise environments. #J ...

Senior Detection & Threat Engineer

Hiring Organisation
Checkout.com
Location
London, UK
Employment Type
Full-time
intrusion techniques across the attack lifecycleHands-on experience buidling detection logic in modern SIEM platforms (e.g Sentinel)Proficienty with scripting and programmaining (e.g. Python, KQL) to build detection pipelines and automationWillingness to challenge bad detections, weak assumptions, and vanity metricsPragmatic mindset: precision and impact beat coverage theatreExperience operating beyond traditional ...

Azure Cloud Security Engineer - Terraform & DevSecOps

Location
City Of London, England, United Kingdom
cloud security architecture, engineering and automation in a highly regulated environment. The role focuses on Azure security, Entra ID, Terraform, Sentinel/KQL and security automation, with strong ownership across real-world cloud environments. You will influence Azure security, identity management and DevSecOps practices, while supporting ...

Threat Intelligence Analyst: Hunt, Detect, and Respond

Location
Greater London, England, United Kingdom
global threat landscapes, analyse intel from OSINT, dark web sources, and feeds, and support incident response for manufacturing and logistics sectors. You will develop KQL queries for threat hunting, produce actionable reports, and collaborate with SOC teams to strengthen detection and response using Microsoft Sentinel and Defender. #J-18808-Ljbffr ...