76 to 100 of 102 Kusto Query Language Jobs in the UK

Senior Cyber Security Analyst

Hiring Organisation
Tria Recruitment
Location
London, UK
Employment Type
Full-time
industry best practice. Detection Engineering & Security AutomationConfigure, optimise and continuously improve Microsoft Sentinel and Microsoft Defender technologies. Develop and tune detection logic using KQL to identify emerging threats and attacker behaviours. Build and maintain automated SOAR workflows using Logic Apps and related technologies. Integrate Microsoft security tooling with third-party … Experience managing stakeholder communications during high-severity incidents. Strong understanding of attacker tactics, techniques and procedures (TTPs).Technical SkillsStrong Microsoft security ecosystem expertise. Advanced KQL experience for investigations, detections and reporting. Experience building automation workflows using Logic Apps or similar technologies. Knowledge of cloud security principles across Azure and ideally ...

Senior SOC Analyst (Outside IR35)

Location
West Midlands, England, United Kingdom
encryption. Ability to think critically under pressure and respond effectively to fast-moving security incidents. Scripting or query experience is highly desirable (SPL, KQL, etc.). Good communication skills from previous roles. Due to the nature and urgency of this post, candidates holding or who have held high level ...

SIEM Engineer

Location
Reading, England, United Kingdom
engineering and Project Amur/ECAF compliance. Scope Onboard and integrate log sources into Sentinel; build custom parsers and data transformations Design and optimise KQL queries; build and tune analytic rules and detection logic Develop Logic Apps/SOAR workflows to automate response Implement CI/CD pipelines (Azure DevOps … positives Key Skills Active SC Clearance (Essential) Strong Microsoft Sentinel engineering, administration and optimisation experience Log source onboarding, custom parsers and data normalisation Advanced KQL development and optimisation Analytic rule/detection logic design and tuning Logic Apps, Playbooks and SOAR automation Azure DevOps/Git CI/CD pipeline ...

Cloud Platform Security Engineer Software engineering London

Location
Greater London, England, United Kingdom
remediation of misconfigurations and vulnerabilities against CIS, NIST, and PCI DSS benchmarks. Security Monitoring Fine tune, and maintain modern SIEM platform (e.g. Sentinel) including KQL detection rules, workbooks, logging pipelines, and AI-assisted alert triage. Map detection coverage against MITRE ATT&CK tactics and techniques. Identify and close visibility gaps … security or other cloud native tooling. Experience with security tools: Microsoft Sentinel, SentinelOne, Netskope, Flashpoint, Wiz or similar tooling. Strong Microsoft Sentinel expertise: KQL, detection rules, workbooks, and logging pipelines. Working knowledge of DLP and threat intelligence monitoring. Experience applying AI/ML to security workflows – automated triage, behavioural analytics ...

Cloud Security Engineer

Hiring Organisation
Hastings Direct
Location
Bexhill, United Kingdom
Welcome to Hastings Direct We’re a digital insurance provider with ambitious plans to become The Best and Biggest in the UK market. Over the past few years, we've made significant investments in our ...

Cloud Security Engineer

Location
Leicester, England, United Kingdom
Welcome to Hastings Direct We’re a digital insurance provider with ambitious plans to become The Best and Biggest in the UK market. Over the past few years, we've made significant investments in our ...

Cloud Security Engineer

Hiring Organisation
Hastings Direct
Location
Bexhill, East Sussex, United Kingdom
Salary
£ 70 K
Welcome to Hastings Direct We’re a digital insurance provider with ambitious plans to become The Best and Biggest in the UK market. Over the past few years, we've made significant investments in our ...

Senior Sales Engineer

Location
Greater London, England, United Kingdom
Okta, endpoint telemetry, etc.) Familiarity with detection frameworks (MITRE ATT&CK) and threat modeling Comfort with APIs, scripting (Python, Bash), and query languages (KQL, SPL, SQL) Able to clearly explain complex technical and security concepts to both technical and non-technical audiences Trusted, credible, and customer-oriented in high ...

SIEM Engineer

Location
Reading, England, United Kingdom
Microsoft Sentinel, ensuring reliable and comprehensive security telemetry. Develop custom parsers and data transformations to normalise and enrich ingested data, and design and optimise KQL queries to support effective threat detection, monitoring and security investigations. Key skills and responsibilities, Integrate and onboard log sources into Microsoft Sentinel, ensuring reliable security … telemetry. Develop custom parsers, data transformations and KQL queries for threat detection and investigation. Create and maintain analytic rules and detection logic aligned to emerging threats and business requirements. Develop Logic Apps and SOAR workflows to automate security response. Implement CI/CD pipelines using Azure DevOps/ ...

Threat Intelligence Analyst

Location
City of Westminster, England, United Kingdom
sharing platforms, and dark web monitoring tools Correlating external intelligence with internal security events using Microsoft Sentinel and Microsoft Defender Developing and maintaining advanced KQL queries to support threat hunting, detection engineering, and incident investigation activities Producing actionable threat intelligence reports, threat actor profiles, IoCs, and executive briefings Supporting … methodologies, and intelligence frameworks such as MITRE ATT&CK, the Diamond Model, and Cyber Kill Chain Advanced knowledge of Microsoft Sentinel, Microsoft Defender, and KQL for threat hunting and investigation Experience working with threat intelligence platforms and dark web monitoring solutions, such as DarkIQ or equivalent Strong analytical skills with ...

Threat Detection Engineer

Hiring Organisation
Millennium Management
Location
London, UK
Employment Type
Full-time
equivalent demonstrable experience.3 years' experience working in a security engineering role, financial industry experience preferred. Experience in creating detections in modern query languages (KQL, SQL, SPL).Possesses security certifications (Security+, OSCP, CISSP, CEH, GCIA, GCIH).Experience with modern security tooling across security domains; network, endpoint, data, identity and cloud. ...

SOC Analyst - Active SC required

Location
Essex, England, United Kingdom
Experience within a Security Operations Centre (SOC) Proficiency with IBM QRadar SIEM for monitoring and incident response Familiarity with common query languages, preferably KQL Understanding of security processes and controls in enterprise environments Ability to work independently with minimal supervision Technical skills in Microsoft Defender, Microsoft Sentinel ...

Security Engineer - SIEM/XDR - London (Hybrid)

Hiring Organisation
Nova Source Technologies
Location
London, United Kingdom
Employment Type
Permanent, Work From Home
Salary
£70,000
Security Engineer (SIEM/XDR) Microsoft Sentinel, Defender, Endpoint, Detection Engineering, Detection-as-Code, KQL, Security Automation, SOAR, Playbooks, Telemetry, Cloud Security, APIs, CI/CD, Infrastructure-as-Code, Python, PowerShell, Windows, Linux, London (Hybrid) This is an exceptional permanent Security Engineer (SIEM/XDR) opportunity to join a leading … engineering or detection engineering experience Hands-on SIEM and XDR tooling, ideally Microsoft Sentinel and Microsoft Defender for Endpoint Detection engineering, detection-as-code, KQL, security content and alert logic Security telemetry, logging pipelines, data quality and telemetry coverage improvement Cloud security engineering and scalable security architecture design Automation, SOAR ...

Security Engineer - Systems Integrator

Location
Cardiff, Wales, United Kingdom
take ownership of security improvements, detection capabilities, and automation across client environments. Responsibilities: Design, implement and optimise security controls. Develop detection capabilities using KQL and Advanced Hunting. Build and maintain Microsoft Sentinel analytical rules. Deploy and manage Content Hub solutions. Tune Microsoft Defender and wider threat policies. Manage phishing simulation … Functions and codeless playbooks where appropriate. Skills/Must Have: Extensive Security Engineering or Senior Security Analysis experience. Strong Microsoft Defender XDR experience. Strong KQL and Advanced Hunting knowledge. Microsoft Sentinel experience. Experience with vulnerability scanning and risk analysis. Strong understanding of security protocols and industry standards. Ability to interpret ...

Security Engineer - Systems Integrator

Location
Greater London, England, United Kingdom
take ownership of security improvements, detection capabilities, and automation across client environments. Responsibilities: Design, implement and optimise security controls. Develop detection capabilities using KQL and Advanced Hunting. Build and maintain Microsoft Sentinel analytical rules. Deploy and manage Content Hub solutions. Tune Microsoft Defender and wider threat policies. Manage phishing simulation … Functions and codeless playbooks where appropriate. Skills/Must Have: Extensive Security Engineering or Senior Security Analysis experience. Strong Microsoft Defender XDR experience. Strong KQL and Advanced Hunting knowledge. Microsoft Sentinel experience. Experience with vulnerability scanning and risk analysis. Strong understanding of security protocols and industry standards. Ability to interpret ...

Senior SOC Manager – Managed Cyber Defence

Location
Glasgow, Scotland, United Kingdom
Line of Service Assurance Industry/Sector Not Applicable Specialism Risk Management Level Senior Manager Job Description & Summary About the role: We are seeking a Senior Manager to lead the day-to-day technical delivery ...

Principal Security Engineer

Location
Leicester, England, United Kingdom
Principal Security Engineer page is loaded## Principal Security Engineerlocations: Bexhill: Leicestertime type: Full timeposted on: Posted Todayjob requisition id: 60013362We’re a digital insurance provider with ambitious plans to become The Best and Biggest in ...

Cyber Security Analyst - Microsoft Security / IAM - Contract

Hiring Organisation
Searchability
Location
Bristol, Avon, United Kingdom
Employment Type
Full-Time
Salary
£400.00 - £500.00 per day
Working with Entra ID, MFA, Conditional Access and RBAC Using Microsoft Sentinel to monitor and investigate security events and incidents Writing and working with KQL queries Investigating suspicious activity, security incidents and emerging threats Supporting vulnerability management and remediation activity Working across the wider Microsoft security ecosystem Identifying opportunities … with: Microsoft Entra ID/Azure AD Identity & Access Management (IAM) Conditional Access Multi-Factor Authentication (MFA) Role-Based Access Control (RBAC) Microsoft Sentinel KQL/custom SIEM queries Microsoft 365/Microsoft security technologies Security incident investigation and remediation Vulnerability management Network and infrastructure security Windows and Linux environments ...

Microsoft Azure Cybersecurity Advisor

Location
Greater London, England, United Kingdom
guidance, helping customers optimize their security defenses and mitigate risks effectively. Microsoft Focus: Utilize your knowledge of Microsoft security products, including Azure, Microsoft Sentinel, KQL, and the Microsoft Defender suite, to offer tailored recommendations and solutions. Relationship Building: Build and nurture strong relationships with customers, acting as a reliable … business and providing informal leadership in cyber security matters. Strong understanding of Microsoft security products and technologies, with proficiency in Azure, Microsoft Sentinel, KQL, and the Microsoft Defender suite or related product lines. Deep understanding of attacker tradecraft and security hardening techniques, enabling you to offer valuable insights and recommendations ...

Cloud Integration Engineer

Location
Witney, England, United Kingdom
Infrastructure as Code (Bicep), ensuring repeatable, secure, and scalable environments.* **Implement and maintain observability**, set up dashboards, alerts, and logging (App Insights, Log Analytics, KQL) so we always know how our integrations are performing.* **Enable secure, private connectivity** for business data using Azure networking features (Private Link, Private DNS, Managed …/test/prod) using CI/CD pipelines.* Familiarity with monitoring and troubleshooting integrations using Azure’s observability tools (App Insights, Log Analytics, KQL).* Understanding of secure networking in Azure (Private Endpoints, Private DNS, VNETs).* A focus on business outcomes and always looking for ways to automate ...

Cyber Security Analyst – Microsoft Security / IAM – Contract

Location
West of England, England, United Kingdom
Working with Entra ID, MFA, Conditional Access and RBAC Using Microsoft Sentinel to monitor and investigate security events and incidents Writing and working with KQL queries Investigating suspicious activity, security incidents and emerging threats Supporting vulnerability management and remediation activity Working across the wider Microsoft security ecosystem Identifying opportunities … Microsoft Entra ID/Azure AD Identity andamp; Access Management (IAM) Conditional Access Multi-Factor Authentication (MFA) Role-Based Access Control (RBAC) Microsoft Sentinel KQL/custom SIEM queries Microsoft 365/Microsoft security technologies Security incident investigation and remediation Vulnerability management Network and infrastructure security Windows and Linux environments ...

Cyber Security Engineer

Location
Greater London, England, United Kingdom
remediation planning, reporting, and automation. Security incident triage, investigation, and response. Microsoft Defender, Entra ID/Active Directory, Conditional Access, and related controls. SIEM query building and KQL. Ransomware resilience, including backup and network segmentation. Cyber Essentials Plus and wider security maturity initiatives. AI, Copilot, Purview, and data security … incident response, and security operations. Microsoft security experience, especially Defender and identity/security controls. SIEM experience and confidence writing or working with queries. KQL is desirable. Someone who is self-sufficient, curious, and comfortable improving processes rather than simply following them. CompTIA Security+ or an equivalent baseline certification. Package ...

Lead Security Analyst

Location
United Kingdom
bench of analysts who can operate at the same standard. Key responsibilities Set the detection engineering standard — author, tune, and peer‐review detections in KQL, SPL, EQL, or Sigma; manage the false‐positive backlog; map coverage to MITRE ATT&CK; and train L1/L2 analysts to write and tune … Security Manager (CISM) CompTIA Advanced Security Practitioner (CASP+) Experience leading detection engineering in a SOC or similar environment— including writing and tuning detections in KQL, SPL, EQL, or Sigma, and managing coverage against MITRE ATT&CK Experience designing or improving a log and telemetry pipeline, including application‐level telemetry from ...

Senior Modern Workplace Engineer

Location
Hinckley, England, United Kingdom
Role Title: Senior Modern Workplace Engineer Business Unit: Group Services Location: Hybrid working from our Leicester, Hinckley or Solihull offices. Applicants should be within reasonable commuting distance of one of these locations. Role Overview We ...

Hybrid Cyber Security Engineer — Lead Vulnerability & AI Security

Location
Greater London, England, United Kingdom
Gravitas Group in London is seeking a Cyber Security Engineer to lead and implement security controls across the organisation. This 12-month FTC focuses on hardening the security posture, delivering projects, and ensuring systems remain ...