26 to 37 of 37 Kusto Query Language Jobs in London

Threat Detection Engineer - Hybrid / Remote

Hiring Organisation
Additional Resources
Location
London, UK
Employment Type
Full-time
maintain and tune the detection catalogueBuild automated reporting dashboards using Microsoft Sentinel workbooksSupport security initiatives including ISO 27001 activities and KQL-based tasksEnsure monitoring coverage across cloud platforms, SaaS apps, and internal systemsContribute to documentation of processes, tools, and detection logicWhat You'll BringMust-Have Skills & Experience: Previously worked … Threat Detection Engineer or in a similar role. Strong proficiency in KQL and hands-on experience with Microsoft SentinelFamiliarity with Microsoft Defender tools (Endpoint & O365)Exposure to Azure cloud logging and Kubernetes environmentsKnowledge of attacker TTPs and MITRE ATT&CK frameworksProactive, collaborative, and innovative mindsetDesirable/Nice-to-Have: Experience ...

Senior Cyber Security Analyst

Hiring Organisation
Tria Recruitment
Location
London, UK
Employment Type
Full-time
industry best practice. Detection Engineering & Security AutomationConfigure, optimise and continuously improve Microsoft Sentinel and Microsoft Defender technologies. Develop and tune detection logic using KQL to identify emerging threats and attacker behaviours. Build and maintain automated SOAR workflows using Logic Apps and related technologies. Integrate Microsoft security tooling with third-party … Experience managing stakeholder communications during high-severity incidents. Strong understanding of attacker tactics, techniques and procedures (TTPs).Technical SkillsStrong Microsoft security ecosystem expertise. Advanced KQL experience for investigations, detections and reporting. Experience building automation workflows using Logic Apps or similar technologies. Knowledge of cloud security principles across Azure and ideally ...

Cloud Platform Security Engineer Software engineering London

Location
Greater London, England, United Kingdom
remediation of misconfigurations and vulnerabilities against CIS, NIST, and PCI DSS benchmarks. Security Monitoring Fine tune, and maintain modern SIEM platform (e.g. Sentinel) including KQL detection rules, workbooks, logging pipelines, and AI-assisted alert triage. Map detection coverage against MITRE ATT&CK tactics and techniques. Identify and close visibility gaps … security or other cloud native tooling. Experience with security tools: Microsoft Sentinel, SentinelOne, Netskope, Flashpoint, Wiz or similar tooling. Strong Microsoft Sentinel expertise: KQL, detection rules, workbooks, and logging pipelines. Working knowledge of DLP and threat intelligence monitoring. Experience applying AI/ML to security workflows – automated triage, behavioural analytics ...

Cloud Engineer

Location
City Of London, England, United Kingdom
Zero Trust controls Build secure infrastructure using Terraform Strengthen CI/CD and DevSecOps security Develop detections and investigations using Microsoft Sentinel & KQL Manage cloud risk through Wiz/CSPM Automate security processes using PowerShell/Python Support ISO 27001, SOC 2 and incident response Strong hands‐on experience across … Azure, Entra ID, Terraform, Sentinel/KQL, Wiz/CSPM, Key Vault and security automation . You don't need every technology listed — we're particularly interested in engineers who can design, secure and improve real-world cloud environments and want genuine ownership. £110k–£140k | Hybrid | City of London #CloudSecurity ...

Threat Detection Engineer

Hiring Organisation
Appcast
Location
London, UK
equivalent demonstrable experience.3 years’ experience working in a security engineering role, financial industry experience preferred.Experience in creating detections in modern query languages (KQL, SQL, SPL).Possesses security certifications (Security+, OSCP, CISSP, CEH, GCIA, GCIH).Experience with modern security tooling across security domains; network, endpoint, data, identity and cloud.Experience ...

Threat Detection Engineer

Hiring Organisation
Millennium Management
Location
London, UK
Employment Type
Full-time
equivalent demonstrable experience.3 years' experience working in a security engineering role, financial industry experience preferred. Experience in creating detections in modern query languages (KQL, SQL, SPL).Possesses security certifications (Security+, OSCP, CISSP, CEH, GCIA, GCIH).Experience with modern security tooling across security domains; network, endpoint, data, identity and cloud. ...

Cyber Security Threat Hunter – 11832SR1

Location
City Of London, England, United Kingdom
Experience translating hunts and red team findings into practical detections and improvements (signal selection, tuning, suppression/thresholding, entity mapping, documentation, and operational handoff) KQL depth and query performance: Comfortable using joins/unions, parsing, time-windowing, summarisation, Essential baselining, and performance-aware query patterns for large datasets ...

Security Engineer - SIEM/XDR - London (Hybrid)

Hiring Organisation
Nova Source Technologies
Location
London, United Kingdom
Employment Type
Permanent, Work From Home
Salary
£70,000
Security Engineer (SIEM/XDR) Microsoft Sentinel, Defender, Endpoint, Detection Engineering, Detection-as-Code, KQL, Security Automation, SOAR, Playbooks, Telemetry, Cloud Security, APIs, CI/CD, Infrastructure-as-Code, Python, PowerShell, Windows, Linux, London (Hybrid) This is an exceptional permanent Security Engineer (SIEM/XDR) opportunity to join a leading … engineering or detection engineering experience Hands-on SIEM and XDR tooling, ideally Microsoft Sentinel and Microsoft Defender for Endpoint Detection engineering, detection-as-code, KQL, security content and alert logic Security telemetry, logging pipelines, data quality and telemetry coverage improvement Cloud security engineering and scalable security architecture design Automation, SOAR ...

Microsoft Azure Cybersecurity Advisor

Location
Greater London, England, United Kingdom
guidance, helping customers optimize their security defenses and mitigate risks effectively. Microsoft Focus Utilize your knowledge of Microsoft security products, including Azure, Microsoft Sentinel, KQL, and the Microsoft Defender suite, to offer tailored recommendations and solutions. Relationship Building Build and nurture strong relationships with customers, acting as a reliable … business and providing informal leadership in cyber security matters. Strong understanding of Microsoft security products and technologies, with proficiency in Azure, Microsoft Sentinel, KQL, and the Microsoft Defender suite or related product lines. Deep understanding of attacker tradecraft and security hardening techniques, enabling you to offer valuable insights and recommendations ...

Performance & Observability Engineer

Location
Greater London, England, United Kingdom
Collaborate with SRE and DevOps teams to optimise CI/CD pipelines for performance improvements. Collaborate with wider IT teams to Implement caching strategies, query optimisation, and autoscaling to enhance system efficiency. Observability Platform Development & Implementation Design and implement end-to-end observability frameworks covering metrics, logs, traces … cloud expenses. Qualifications, Skills and Experience Technical Skills Experience in using and maintaining Observability & APM Tools – Grafana experience is essential Experience of using KQL Performance Testing & Load Testing Cloud & Infrastructure Monitoring – AWS CloudWatch, Azure Monitor, GCP Operations Suite, Kubernetes Observability. Knowledge of Log Aggregation & Analysis – eg: Grafana Loki, Splunk ...

Senior Application Security Engineer

Location
Greater London, England, United Kingdom
We’re looking for a Senior Application Security Engineer to join our expanding Information Security team. If you are a hands‐on AppSec expert who enjoys working deep in the SDLC, partnering with talented engineers ...

Detection Content Engineer: KQL & Sentinel Automation

Location
Greater London, England, United Kingdom
threat-informed research, design scalable automation for onboarding and enrichment, and advise clients on detection logic with strong MS security stack skills and deep KQL expertise. #J-18808-Ljbffr ...