1 to 25 of 26 Remote/Hybrid Kusto Query Language Jobs in the UK

Sentinel Engineer

Hiring Organisation
Opus Recruitment Solutions
Location
Remote work, United Kingdom
Employment Type
Contract
Contract Rate
£500 - £550/day
into Microsoft Sentinel . Develop and maintain analytics rules, alerting capabilities and detection use cases. Create and optimise Kusto Query Language (KQL) queries for threat hunting, incident investigation and reporting. Integrate and onboard new log sources and security tooling into Sentinel. Configure and support Azure Monitor … Analytics Azure Monitor Microsoft Defender XDR Microsoft Defender for Endpoint Microsoft Defender for Cloud Microsoft 365 Security Kusto Query Language (KQL) Azure Logic Apps Azure Lighthouse Experience Minimum 5 years' experience within Cyber Security, Security Engineering, SOC, SIEM Engineering or related disciplines. Strong understanding of SIEM, SOAR ...

SC Cleared Splunk SIEM Engineer

Hiring Organisation
Hays
Location
Knutsford, Cheshire, North West, United Kingdom
Employment Type
Contract, Work From Home
Contract Rate
£500.0 - £638 per day + Up to £638 per day Inside IR35
Security & Modern Infrastructure: Proficiency with AWS/Azure cloud security, containerised environments, and SaaS-based security solutions. Programming & Scripting: Advanced skills in Python, PowerShell, KQL, SPL, and SQL for automation, custom integrations, and advanced analytics development. Security Certifications: Professional certifications such as CISSP, GCIH, GCFA, Splunk Certified Architect, or Microsoft ...

Splunk SIEM Engineer

Hiring Organisation
Experis
Location
Knutsford, Cheshire, United Kingdom
Employment Type
Contract
Security & Modern Infrastructure: Proficiency with AWS/Azure cloud security, containerized environments, and SaaS-based security solutions. Programming & Scripting: Advanced skills in Python, PowerShell, KQL, SPL, and SQL for automation, custom integrations, and advanced analytics development. Security Certifications: Professional certifications such as CISSP, GCIH, GCFA, Splunk Certified Architect, or Microsoft ...

SOC Engineer

Hiring Organisation
Proactive Appointments
Location
Milton Keynes, Buckinghamshire, England, United Kingdom
Employment Type
Full-Time
Salary
£50,000 - £55,000 per annum
documentation, runbooks, and operational procedures. Skills & Experience Experience engineering and supporting SIEM platforms, ideally Microsoft Sentinel. Strong scripting and automation skills (Python, PowerShell, Bash, KQL). Experience with SOAR technologies and security automation. Knowledge of detection engineering and threat hunting. Strong understanding of Windows and Linux logging. Good networking knowledge ...

Principal Microsoft Defender XDR, IRM & Deception Engineer

Hiring Organisation
WTW
Location
Greater London, United Kingdom
Employment Type
Full Time
Skills & Experience: Hands-on experience with: Open-source and commercial deception/honeypot platforms (e.g., Thinkst Canary, T-Pot, Cowrie, OpenCanary, Zscaler Deception) Advanced KQL for detection engineering and threat hunting at scale Detection-as-code, CI/CD of detection content, and security content management Strong knowledge of adversary ...

Cyber Security Engineer

Hiring Organisation
DCV Technologies Limited
Location
Tring, Hertfordshire, South East, United Kingdom
Employment Type
Contract
Contract Rate
£65,000
operations (coverage management, escalation handling, policy tuning). Familiarity with Microsoft Defender suite and/or Microsoft Sentinel. Scripting/automation skills (PowerShell, KQL, Python). Knowledge of ransomware recovery patterns (immutable backups, restore validation, offline documentation). Exposure to audit/compliance requirements (ISO 27001, NIST, CIS) and evidence ...

Senior Cyber Consultant

Hiring Organisation
Reed Technology
Location
United Kingdom
Employment Type
Permanent
Salary
GBP Annual
MITRE ATT&CK, develop response playbooks, and implement Detection-as-Code best practices. Key Requirements Experience with SIEM platforms (Microsoft Sentinel preferred) Strong KQL and detection engineering skills SOAR automation and playbook development experience Python and/or PowerShell scripting XDR/EDR experience Knowledge of MITRE ...

Cyber Security Lead

Hiring Organisation
GR Consulting
Location
London, South East, England, United Kingdom
Employment Type
Full-Time
Salary
£100,000 per annum, Inc benefits
Microsoft Sentinel. Proven ability to design and implement Conditional Access, identity protection, and device compliance policies. Experience developing detection rules, analytics, and automation using KQL and Sentinel playbooks. Solid understanding of Zero Trust architecture and practical implementation across enterprise environments. Strong knowledge of endpoint hardening, EDR tuning, and modern attack ...

2nd / 3rd Line Security Analyst

Hiring Organisation
17918
Location
Reading, Berkshire, United Kingdom
incidents from triage through to closure Hands-on experience writing and tuning SIEM detection logic, with a solid understanding of MITRE ATT&CK and KQL (or equivalent) Practical scripting/automation experience (Python, Logic Apps, REST APIs) or hands-on SOAR platform configuration Working knowledge of several of: Microsoft Sentinel ...

Data Governance Senior Consultant

Hiring Organisation
Jobleads-UK
Location
Park Central, England, United Kingdom
Enterprise architecture frameworks (TOGAF, SABSA, or equivalent)Strong understanding of data classification models, and risk scoringAbility to design and optimise enterprise Purview deploymentsKnowledge of KQL, PowerShell, and Microsoft Graph is a plus.Capability to analyse unstructured and structured data estatesAbility to lead technical teams and influence senior leadershipAbility to work across ...

Data Governance Senior Consultant

Hiring Organisation
Capgemini
Location
City and Borough of Birmingham, United Kingdom
Employment Type
Full Time
frameworks (TOGAF, SABSA, or equivalent) Strong understanding of data classification models, and risk scoring Ability to design and optimise enterprise Purview deployments Knowledge of KQL, PowerShell, and Microsoft Graph is a plus. Capability to analyse unstructured and structured data estates Ability to lead technical teams and influence senior leadership Ability ...

Data Governance Senior Consultant

Hiring Organisation
Jobleads-UK
Location
United Kingdom
frameworks (TOGAF, SABSA, or equivalent)* Strong understanding of data classification models, and risk scoring* Ability to design and optimise enterprise Purview deployments* Knowledge of KQL, PowerShell, and Microsoft Graph is a plus.* Capability to analyse unstructured and structured data estates* Ability to lead technical teams and influence senior leadership* Ability ...

Security Operations Team Leader

Hiring Organisation
Harvey Nash
Location
Darlington, County Durham, North East, United Kingdom
Employment Type
Temporary, Work From Home
Salary
£75,000
Security Operations, monitoring, detection and response activities. Drive improvements across Microsoft Sentinel, Microsoft Defender and the wider M365 security ecosystem. Utilise KQL to enhance threat hunting, reporting, automation and detection capabilities. Manage third-party security vendors, ensuring service levels and contractual obligations are delivered. Support security audits, risk management activities ...

Senior Security Engineering Consultant

Hiring Organisation
Jobleads-UK
Location
Basingstoke, England, United Kingdom
operate and evolve their detection capabilities. Responsibilities Deliver Design and deliver detection rulesets across SIEM and XDR platforms Develop and tune detection logic using KQL or equivalent query languages Design detection use cases aligned to MITRE ATT&CK and real‐world attack techniques Map customer log sources to detection … Experience Strong hands‐on experience with SIEM engineering, including developing and tuning detection rules, with Microsoft Sentinel preferred Experience writing detection logic using KQL or similar query languages Proven experience designing and implementing SOAR automations and playbooks such as Logic Apps, Cortex XSOAR or similar Scripting and automation capability ...

Senior Security Engineering Team Lead

Hiring Organisation
Interface Recruitment
Location
Nationwide, United Kingdom
Employment Type
Permanent
Salary
£82500 - £85500/annum 25 days / PHI / PEN / DIS
including: Microsoft Defender XDR Defender for Endpoint Defender for Identity Microsoft Sentinel Logic Apps SOAR Automation Microsoft Purview Qualys XM Cyber CyberArk Detection Engineering KQL Threat Hunting Platform Engineering About You We're looking for someone who combines deep technical expertise with natural leadership skills. You'll likely have experience ...

Threat Detection Engineer - Hybrid / Remote

Hiring Organisation
Additional Resources
Location
Westminster, City of Westminster, Greater London, United Kingdom
Employment Type
Permanent
Salary
£60000 - £80000/annum
maintain and tune the detection catalogue Build automated reporting dashboards using Microsoft Sentinel workbooks Support security initiatives including ISO 27001 activities and KQL-based tasks Ensure monitoring coverage across cloud platforms, SaaS apps, and internal systems Contribute to documentation of processes, tools, and detection logic What You’ll Bring Must … Have Skills & Experience: Previously worked as a Threat Detection Engineer or in a similar role. Strong proficiency in KQL and hands-on experience with Microsoft Sentinel Familiarity with Microsoft Defender tools (Endpoint & O365) Exposure to Azure cloud logging and Kubernetes environments Knowledge of attacker TTPs and MITRE ATT&CK frameworks ...

Threat Detection Engineer - Hybrid / Remote

Hiring Organisation
Additional Resources Ltd
Location
London, South East, England, United Kingdom
Employment Type
Full-Time
Salary
£60,000 - £80,000 per annum
maintain and tune the detection catalogue Build automated reporting dashboards using Microsoft Sentinel workbooks Support security initiatives including ISO 27001 activities and KQL-based tasks Ensure monitoring coverage across cloud platforms, SaaS apps, and internal systems Contribute to documentation of processes, tools, and detection logic What You’ll Bring Must … Have Skills & Experience: Previously worked as a Threat Detection Engineer or in a similar role. Strong proficiency in KQL and hands-on experience with Microsoft Sentinel Familiarity with Microsoft Defender tools (Endpoint & O365) Exposure to Azure cloud logging and Kubernetes environments Knowledge of attacker TTPs and MITRE ATT&CK frameworks ...

Security Engineer (SIEM / XDR) Microsoft Sentinel, Defender - Remote

Hiring Organisation
Nova Source Technologies
Location
United Kingdom
Employment Type
Permanent, Work From Home
Security Engineer (SIEM/XDR) Microsoft Sentinel, Defender, Endpoint, Detection Engineering, Detection-as-Code, KQL, Security Automation, SOAR, Playbooks, Telemetry, Cloud Security, APIs, CI/CD, Infrastructure-as-Code, Python, PowerShell, Windows, Linux, Remote (with UK wide travel) This is an exceptional permanent Security Engineer (SIEM/XDR) opportunity … security engineering or detection engineering experience Hands-on SIEM and XDR tooling Microsoft Sentinel and Microsoft Defender for Endpoint Detection engineering, detection-as-code, KQL, security content and alert logic Automation, SOAR, playbooks, enrichment workflows and response improvement Scripting/programming with Python and/or PowerShell Infrastructure-as-code ...

Security Engineer - SIEM/XDR - Remote w/Travel (UK)

Hiring Organisation
Nova Source Technologies
Location
United Kingdom
Employment Type
Permanent, Work From Home
Salary
£70,000
Security Engineer (SIEM/XDR) Microsoft Sentinel, Defender, Endpoint, Detection Engineering, Detection-as-Code, KQL, Security Automation, SOAR, Playbooks, Telemetry, Cloud Security, APIs, CI/CD, Infrastructure-as-Code, Python, PowerShell, Windows, Linux, Remote (with UK wide travel) This is an exceptional permanent Security Engineer (SIEM/XDR) opportunity … engineering or detection engineering experience Hands-on SIEM and XDR tooling, ideally Microsoft Sentinel and Microsoft Defender for Endpoint Detection engineering, detection-as-code, KQL, security content and alert logic Security telemetry, logging pipelines, data quality and telemetry coverage improvement Cloud security engineering and scalable security architecture design Automation, SOAR ...

Principal Security Engineer

Hiring Organisation
Jobleads-UK
Location
Leicester, England, United Kingdom
Principal Security Engineer page is loaded## Principal Security Engineerlocations: Bexhill: Leicestertime type: Full timeposted on: Posted Todayjob requisition id: 60013362We’re a digital insurance provider with ambitious plans to become The Best and Biggest in ...

SOC Engineer

Hiring Organisation
IBEX RECRUITMENT LTD
Location
North West, United Kingdom
Employment Type
Permanent, Work From Home
Salary
£70,000
Engineering and maintaining Microsoft Sentinel , Defender XDR , and Log Analytics platforms Onboarding and normalising log sources across hybrid/cloud environments Writing and tuning KQL detection rules and analytics logic Building SOAR playbooks (Logic Apps, automation workflows) to reduce manual effort Managing telemetry ingestion, parsers, and data retention for cost … contributing to team development Acting as technical SME during incidents What we're looking for: Deep experience with Microsoft Sentinel , Defender suite , and KQL Strong scripting/automation skills ( PowerShell, Python, Logic Apps ) Solid understanding of MITRE ATT&CK , NCSC CAF , NIST CSF Stakeholder management able to translate technical complexity ...

SOC Engineer

Hiring Organisation
17918
Location
London, United Kingdom
Engineering and maintaining Microsoft Sentinel , Defender XDR , and Log Analytics platforms Onboarding and normalising log sources across hybrid/cloud environments Writing and tuning KQL detection rules and analytics logic Building SOAR playbooks (Logic Apps, automation workflows) to reduce manual effort Managing telemetry ingestion, parsers, and data retention for cost … contributing to team development Acting as technical SME during incidents What we're looking for: Deep experience with Microsoft Sentinel , Defender suite , and KQL Strong scripting/automation skills ( PowerShell, Python, Logic Apps ) Solid understanding of MITRE ATT&CK , NCSC CAF , NIST CSF Stakeholder management able to translate technical complexity ...

Lead Security Analyst

Hiring Organisation
Hackajob Ltd
Location
Bristol, Avon, South West, United Kingdom
Employment Type
Permanent, Part Time, Work From Home
Salary
£80,000
bench of analysts who can operate at the same standard. Key Responsibilities Set the detection engineering standard - author, tune, and peer-review detections in KQL, SPL, EQL, or Sigma; manage the false-positive backlog; map coverage to MITRE ATT&CK; and train L1/L2 analysts to write and tune … Security Manager (CISM) CompTIA Advanced Security Practitioner (CASP+) Experience leading detection engineering in a SOC or similar environment - including writing and tuning detections in KQL, SPL, EQL, or Sigma, and managing coverage against MITRE ATT&CK Experience designing or improving a log and telemetry pipeline, including application-level telemetry from ...

Senior Security Specialist - Threat Hunting

Hiring Organisation
Yolk Recruitment Limited
Location
Cardiff, South Glamorgan, Wales, United Kingdom
Employment Type
Permanent
hypothesis-driven approaches. Investigate complex security incidents and provide technical escalation within the CSOC. Develop and optimise SIEM detections, analytics, use cases and KQL queries to improve threat detection and reduce false positives. Identify gaps in logging, monitoring and telemetry across cloud, identity, endpoint, network and application environments. Analyse threat … related technical discipline. Strong knowledge of cyber security operations, threat hunting, incident response and security monitoring. Experience with SIEM platforms (ideally Microsoft Sentinel), KQL or similar analytics tools. Good understanding of cloud, endpoint, identity, network and application security. Knowledge of security frameworks such as NIST or ISO 27001. Experience Proven ...

Senior Technical Support Specialist

Hiring Organisation
Vermelo RPO
Location
Charing Heath, Kent, United Kingdom
Employment Type
Permanent
Salary
GBP Annual
updates, product changes, new customer deployments and connectivity investigations Investigate API and platform-related issues using tools such as Postman, Azure logs and basic KQL queries Recreate technical issues, validate payloads and identify whether problems relate to configuration, customer usage, devices, data or genuine platform defects Provide clear, evidence-based … status codes, API keys, authentication and permissions Experience using Postman or similar API testing tools Exposure to Azure monitoring tools, application logs or basic KQL queries Strong written and verbal communication skills A calm, organised and customer-focused approach Excellent attention to detail and technical documentation skills Experience with ...