26 to 50 of 102 Kusto Query Language Jobs in the UK

Security Operations Analyst (SOC analyst)

Location
Greater London, England, United Kingdom
approximately once every five weeks). Preferred Qualifications, Capabilities, and Skills Experience with detection engineering and writing/tuning detection content (e.g., Sigma, YARA, KQL, SPL, or equivalent). Hands-on threat hunting experience using hypothesis-driven methodologies. Familiarity with SOAR platforms, scripting/automation, and AI-assisted security tooling. ...

Logs Specialist

Location
Maidenhead, England, United Kingdom
proactively provide technical guidance to unlock more log data volume and user adoption.* Conduct "Best Practice" workshops focused on log-based alerting, DQL (Dynatrace Query Language) proficiency, and dashboarding.## **What will help you succeed****Qualifications & Requirements*** Experience: 5+ years in a domain, specialist, pre-sales, professional services … role, with at least 3 years specifically focused on Log Management or Big Data analytics.* Technical Depth: Advanced proficiency in Query Languages (e.g., Splunk SPL, Kusto QL, SQL, or Lucene).* Deep understanding of Log Ingestion pipelines and "Telemetry Pipelines" (Cribl, BindPlane, Vector).* Hands-on experience with ...

SOC Analyst

Location
Harlow, England, United Kingdom
QRadar SIEM Experience monitoring, triaging, and investigating security incidents Knowledge of incident response lifecycle and root cause analysis Experience with Microsoft Defender (essential) KQL knowledge desirable Ability to work independently and manage complex cyber investigations Technical Exposure: IBM QRadar Microsoft Defender/EDR Microsoft Sentinel (desirable) Microsoft Entra ID/ ...

SOC Analyst (MS Sentinel & Defender, SC Cleared)

Location
Harlow, England, United Kingdom
including Microsoft Sentinel Experience monitoring, triaging, and investigating security incidents Knowledge of incident response lifecycle and root cause analysis Experience with Microsoft Defender (essential) KQL knowledge desirable Ability to work independently and manage complex cyber investigations Technical Exposure: IBM QRadar Microsoft Defender/EDRMicrosoft Sentinel (essential) Microsoft Entra ID/ ...

Lead Threat Detection Engineer

Location
Greater London, England, United Kingdom
than purely responding to SOC alerts Strong SIEM experience – Microsoft Sentinel, Splunk or similar Cloud security experience across AWS, GCP and/or Azure KQL, SPL or similar querying experience Python scripting/security automation Terraform/Infrastructure as Code exposure Experience with threat intelligence or threat hunting Strong ownership ...

Azure Platform Architect

Hiring Organisation
Cognitive Group | Part of the Focus Cloud Group
Location
City of London, London, United Kingdom
Policy, Management Groups and subscription architecture Azure Migrate and associated discovery tooling Microsoft Defender for Cloud and Microsoft Sentinel Azure Monitor, Log Analytics and KQL Zero Trust architecture High availability and disaster recovery FinOps and cloud cost optimisation Use of GitHub Copilot to accelerate Infrastructure as Code development The Person ...

Azure Platform Architect

Location
Slough, England, United Kingdom
Policy, Management Groups and subscription architecture Azure Migrate and associated discovery tooling Microsoft Defender for Cloud and Microsoft Sentinel Azure Monitor, Log Analytics and KQL Zero Trust architecture High availability and disaster recovery FinOps and cloud cost optimisation Use of GitHub Copilot to accelerate Infrastructure as Code development The Person ...

SecOps Engineer

Location
City Of London, England, United Kingdom
with the ability to write detections, tune content and operate at a deep technical level Solid scripting ability, for example in Python, PowerShell or KQL, with a working understanding of APIs and integration patterns Practical understanding of common attack techniques mapped to MITRE ATT&CK, and how they manifest ...

Data Governance Managing Consultant

Location
Greater London, England, United Kingdom
Enterprise architecture frameworks (TOGAF, SABSA, or equivalent)Strong understanding of data classification models, and risk scoringAbility to design and optimise enterprise Purview deploymentsKnowledge of KQL, PowerShell, and Microsoft Graph is a plus.Capability to analyse unstructured and structured data estatesAbility to lead technical teams and influence senior leadershipAbility to work across ...

Security Engineer

Hiring Organisation
NTT DATA
Location
Birmingham, United Kingdom
Technical Skills Proven hands-on experience with SIEM platforms such as Splunk, QRadar, Sentinel, Microsoft Defender, or Chronicle.Expertise with SIEM query languages (e.g., KQL, SPL, AQL) and strong knowledge of log normalization and parsing.Proficiency in scripting (e.g., Python, PowerShell) to automate tasks and build SOC efficiencies.Deep familiarity with cyber ...

Senior SOC Engineer

Location
Glasgow, Lanarkshire, United Kingdom
Proven expertise in IBM QRadar and SIEM engineering. Strong knowledge of log formats, parsing, and normalisation. Proficiency in SIEM query languages such as KQL, SPL, AQL. Scripting experience with Python or PowerShell for automation. Deep understanding of threat detection, incident response, and the cyber kill chain. Familiarity with frameworks ...

Senior Security Engineering Consultant

Hiring Organisation
Infosec
Location
Basingstoke, Hampshire, South East, United Kingdom
Employment Type
Permanent, Work From Home
Salary
£80,000
functions, tooling, and detection capabilities. Key Responsibilities: Design and deliver detection rulesets across SIEM and XDR platforms Develop and tune detection logic using KQL or equivalent query languages Design detection use cases aligned to MITRE ATT&CK and real-world attack techniques Map customer log sources to detection … Requirements: Strong hands-on experience with SIEM engineering, including developing and tuning detection rules, with Microsoft Sentinel preferred Experience writing detection logic using KQL or similar query languages Proven experience designing and implementing SOAR automations and playbooks such as Logic Apps, Cortex XSOAR or similar Scripting and automation capability ...

SC-Cleared SIEM Engineer: Sentinel & SOAR Automation

Location
Reading, England, United Kingdom
onboard and integrate security log sources into Microsoft Sentinel, delivering reliable telemetry and comprehensive threat visibility. You will develop custom parsers, transformations and KQL queries, and design SIEM detections aligned to evolving threats. CI/CD pipelines with Azure DevOps/Git enable controlled deployments. #J-18808-Ljbffr ...

SC Cleared SIEM Engineer: Azure Sentinel & SOAR Expert

Location
Havant, England, United Kingdom
month contract. The role focuses on onboarding log sources into Microsoft Sentinel, developing parsers, and creating automated detection and response workflows. Responsibilities include tuning KQL queries, building analytic rules, and deploying SIEM content via CI/CD pipelines to multiple environments. Strong familiarity with SOAR and Logic Apps is essential. ...

SC Cleared SIEM Engineer: Azure Sentinel & SOAR Expert

Location
Reading, England, United Kingdom
month contract. The role focuses on onboarding log sources into Microsoft Sentinel, developing parsers, and creating automated detection and response workflows. Responsibilities include tuning KQL queries, building analytic rules, and deploying SIEM content via CI/CD pipelines to multiple environments. Strong familiarity with SOAR and Logic Apps is essential. ...

security engineer in legal services

Location
Greater London, England, United Kingdom
Sentinel, Exabeam, Splunk, or equivalent Experience with vulnerability management using Tenable or equivalent enterprise toolsets Experience with scripting and automation, preferably PowerShell, and KQL or similar Experience with Data Loss Prevention solutions, including MS Purview Compliance Manager Nice to have: CISSP, CREST Practitioner Security Analyst (CPSA), Palo Alto Networks Certified ...

Senior Security Engineer - Contract

Location
Greater London, England, United Kingdom
security risk clearly to engineering and product audiences. A growth mindset and genuine curiosity to keep learning. SC-200 (Microsoft Security Operations Analyst) certification. KQL proficiency for detection rule authoring and threat hunting. Experience working in a similar fintech or financial services environment All are welcome: #J-18808-Ljbffr ...

Senior Security Architect - SecOps and Vulnerability Management

Hiring Organisation
Hackajob Ltd
Location
South West London, London, United Kingdom
Employment Type
Permanent
advising and influencing enterprise SIEM platforms (e.g., Microsoft Sentinel, Splunk, Chronicle/SecOps). Must be proficient in writing/reviewing advanced detection logic (KQL, SPL, or YARA rules). Deep execution knowledge of generating, managing, and analyzing Software Bills of Materials (SBOMs using frameworks like CycloneDX or SPDX ...

Senior Security Operations Analyst

Location
Leeds, England, United Kingdom
pressured environment and whilst dealing with competing priorities Demonstrable experience with at least one major SIEM and EDR platform, additional hands‐on KQL/SPL, PowerShell/Python experience preferred Demonstrable experience with Security Orchestration and Automation Strong understanding of ITSM workflows, implementing operational processes, and service delivery Practical experience ...

Principal Security Design Consultant

Location
Greater London, England, United Kingdom
500. Hands‐on experience with other SIEM and EDR/XDR platforms such as CrowdStrike, Splunk, QRadar, Rapid7 or Elastic. Experience with KQL, Sigma, Logic Apps, PowerShell or other automation and detection‐as‐code approaches. Knowledge of MITRE ATT&CK, NIST SP 800-61, NCSC CAF and recognised security operations … SIEM, EDR/XDR or protective monitoring transformations. Deep practical design experience with Microsoft Sentinel, Defender XDR and Defender for Endpoint, including Log Analytics, KQL, data connectors, analytics and automation. Full lifecycle delivery experience from discovery and HLD/LLD development through migration, testing, service transition and implementation assurance. Experience ...

Senior Security Engineering Consultant

Hiring Organisation
Matchtech
Location
Basingstoke, United Kingdom
automate their SOC functions, tooling, and detection capabilities.Key Responsibilities:Design and deliver detection rulesets across SIEM and XDR platformsDevelop and tune detection logic using KQL or equivalent query languagesDesign detection use cases aligned to MITRE ATT&CK and real-world attack techniquesMap customer log sources to detection use cases … detection outcomesJob Requirements:Strong hands-on experience with SIEM engineering, including developing and tuning detection rules, with Microsoft Sentinel preferredExperience writing detection logic using KQL or similar query languagesProven experience designing and implementing SOAR automations and playbooks such as Logic Apps, Cortex XSOAR or similarScripting and automation capability using ...

Senior Security Engineering Consultant

Hiring Organisation
Nomios
Location
Basingstoke, United Kingdom
evolve their detection capabilities.ResponsibilitiesKey responsibilities of the role include:DeliverDesign and deliver detection rulesets across SIEM and XDR platformsDevelop and tune detection logic using KQL or equivalent query languagesDesign detection use cases aligned to MITRE ATT&CK and real-world attack techniquesMap customer log sources to detection use cases … Skills and ExperienceStrong hands-on experience with SIEM engineering, including developing and tuning detection rules, with Microsoft Sentinel preferred Experience writing detection logic using KQL or similar query languages Proven experience designing and implementing SOAR automations and playbooks such as Logic Apps, Cortex XSOAR or similar Scripting and automation ...

IAM Consultant/Developer (Microsoft Entra ID) - Contract role, UK, fully remote

Location
United Kingdom
identity lifecycle automation, ideally via the Microsoft Graph PowerShell SDK. Comfortable working independently and communicating migration risk/status to non-technical stakeholders. Desirable: KQL for log analysis in Microsoft Sentinel or Azure Monitor. Experience with Entra ID B2B/B2C. Background with an alternative IAM platform (ForgeRock, Ping, Okta ...

Junior Cyber Security Engineer

Location
Greater London, England, United Kingdom
develop cyber security skills, including Microsoft Security tools (e.g. Defender, Entra, Sentinel), cloud platforms (AWS/Azure), and scripting/coding (e.g. Terraform, Python, KQL) — product‐specific training provided Awareness of other security tools and their uses (e.g. Qualys, Akamai, Valimail) Relevant IT or cyber security qualification (Desirable) What ...

3rd Line Security Analyst

Location
Reading, England, United Kingdom
carry out malware analysis and threat validation. Design, implement and optimise detection content across Microsoft Sentinel, Defender XDR, CrowdStrike and associated platforms, developing advanced KQL queries and analytics rules aligned to MITRE ATT&CK. Act as senior technical owner for security platforms including Microsoft Sentinel, Defender XDR, CrowdStrike Falcon, Entra … Microsoft Defender XDR, CrowdStrike Falcon and associated security technologies. Proven experience in incident response, threat hunting, malware analysis, digital forensics and security investigations. Advanced KQL skills, with the ability to develop and optimise complex detections and threat hunting queries. Strong scripting and automation experience using PowerShell and/or Python ...