1 to 25 of 26 Kusto Query Language Jobs

Exchange SME

Hiring Organisation
Morson Edge
Location
London, United Kingdom
Employment Type
Contract
Contract Rate
£400 - 440 per day
Implement security best practices, including privileged access management and least privilege. Microsoft Sentinel Deploy, configure, and manage Microsoft Sentinel. Develop and maintain analytics rules, KQL queries, workbooks, and automation. Investigate security incidents and suspicious activity. Integrate Microsoft Sentinel with Active Directory, Microsoft 365, Defender, and other security platforms. Develop Logic … Services Group Policy DNS, DHCP, TCP/IP PowerShell Microsoft 365 Microsoft Entra ID Microsoft Defender Microsoft Sentinel Kusto Query Language (KQL) Windows Server Azure Hybrid identity and Exchange environments Security monitoring and incident response Please send your CV fo immediate interview ...

SC Cleared Splunk SIEM Engineer

Hiring Organisation
Hays
Location
Knutsford, Cheshire, North West, United Kingdom
Employment Type
Contract, Work From Home
Contract Rate
£500.0 - £638 per day + Up to £638 per day Inside IR35
Security & Modern Infrastructure: Proficiency with AWS/Azure cloud security, containerised environments, and SaaS-based security solutions. Programming & Scripting: Advanced skills in Python, PowerShell, KQL, SPL, and SQL for automation, custom integrations, and advanced analytics development. Security Certifications: Professional certifications such as CISSP, GCIH, GCFA, Splunk Certified Architect, or Microsoft ...

SOC Engineer

Hiring Organisation
Proactive Appointments
Location
Milton Keynes, Buckinghamshire, England, United Kingdom
Employment Type
Full-Time
Salary
£50,000 - £55,000 per annum
documentation, runbooks, and operational procedures. Skills & Experience Experience engineering and supporting SIEM platforms, ideally Microsoft Sentinel. Strong scripting and automation skills (Python, PowerShell, Bash, KQL). Experience with SOAR technologies and security automation. Knowledge of detection engineering and threat hunting. Strong understanding of Windows and Linux logging. Good networking knowledge ...

Principal Microsoft Defender XDR, IRM & Deception Engineer

Hiring Organisation
WTW
Location
Greater London, United Kingdom
Employment Type
Full Time
Skills & Experience: Hands-on experience with: Open-source and commercial deception/honeypot platforms (e.g., Thinkst Canary, T-Pot, Cowrie, OpenCanary, Zscaler Deception) Advanced KQL for detection engineering and threat hunting at scale Detection-as-code, CI/CD of detection content, and security content management Strong knowledge of adversary ...

Azure Platform Engineer

Hiring Organisation
Cognitive Group | Part of the Focus Cloud Group
Location
England, United Kingdom
Vault and Microsoft Defender for Cloud Azure App Services, Functions, Logic Apps, Storage Accounts and Azure SQL Azure Monitor, Log Analytics, Application Insights and KQL Experience supporting enterprise Azure Landing Zone environments Azure DevOps, Git and CI/CD pipelines Infrastructure as Code using Terraform, Bicep or ARM Templates Good ...

Cyber Security Engineer

Hiring Organisation
DCV Technologies Limited
Location
Tring, Hertfordshire, South East, United Kingdom
Employment Type
Contract
Contract Rate
£65,000
operations (coverage management, escalation handling, policy tuning). Familiarity with Microsoft Defender suite and/or Microsoft Sentinel. Scripting/automation skills (PowerShell, KQL, Python). Knowledge of ransomware recovery patterns (immutable backups, restore validation, offline documentation). Exposure to audit/compliance requirements (ISO 27001, NIST, CIS) and evidence ...

Associate Security Analyst

Hiring Organisation
NonStop Consulting
Location
London, United Kingdom
Employment Type
Contract
Contract Rate
£650 - £700/day
Analyst. Hands-on experience with SIEM (Splunk preferred; Microsoft Sentinel or equivalent also considered). Experience with M365 security tooling (e.g. Microsoft Defender, Sentinel, KQL). Good understanding of threat actors' tools, techniques and procedures . Strong analytical, problem-solving and communication skills. Nice to have Further experience with Splunk ...

2nd / 3rd Line Security Analyst

Hiring Organisation
XACT PLACEMENTS LIMITED
Location
Reading, Berkshire, South East, United Kingdom
Employment Type
Permanent
Salary
£60,000
incidents from triage through to closure Hands-on experience writing and tuning SIEM detection logic, with a solid understanding of MITRE ATT&CK and KQL (or equivalent) Practical scripting/automation experience (Python, Logic Apps, REST APIs) or hands-on SOAR platform configuration Working knowledge of several of: Microsoft Sentinel ...

Senior Application Security Engineer / DevSecOps Engineer

Hiring Organisation
Additional Resources
Location
London, United Kingdom
Employment Type
Permanent
Salary
£80000 - £90000/annum
scale medical research. You will work closely with engineering, architecture and cloud teams to integrate security throughout the software development lifecycle. Microsoft Azure and KQL experience are essential, alongside relevant experience in CI/CD, Kubernetes, API security, security-as-code and security automation. This is a hands-on application ...

SC Cleared Security Analyst

Hiring Organisation
IF Recruitment Ltd
Location
London, United Kingdom
Employment Type
Contract
Contract Rate
GBP Annual
SIEM) to support the investigation and response to cyber incidents. Experience working with Splunk Experience of M365 (MS Defender/Sentinel/KQL) Experience with cloud environment such as AWS This work has been determined as falling inside IR35. ...

Performance and Monitoring Engineer

Hiring Organisation
Solus Accident Repair Centres
Location
Birchanger, Hertfordshire, United Kingdom
Employment Type
Permanent
Salary
GBP 40,000 - 50,000 Annual
Analytics, Defender for Cloud) Excellent understanding of cloud performance, IaaS/PaaS, networking fundamentals, API performance and capacity modelling Skilled in dashboards, log queries (KQL), custom metrics and performance analysis Ability to diagnose complex issues across infrastructure, networks, applications or databases Confident scripting and automation skills (PowerShell, Azure Automation, Graph ...

Performance and Monitoring Engineer

Hiring Organisation
Solus Accident Repair Centres
Location
Stansted, Essex, South East, United Kingdom
Employment Type
Permanent
Salary
£50,000
Analytics, Defender for Cloud) Excellent understanding of cloud performance, IaaS/PaaS, networking fundamentals, API performance and capacity modelling Skilled in dashboards, log queries (KQL), custom metrics and performance analysis Ability to diagnose complex issues across infrastructure, networks, applications or databases Confident scripting and automation skills (PowerShell, Azure Automation, Graph ...

Security Engineer

Hiring Organisation
Tiro Partners Limited
Location
London, South East, England, United Kingdom
Employment Type
Full-Time
Salary
£60,000 - £90,000 per annum
identify and remediate vulnerabilities. About you You’ll have strong hands-on experience in application security and ideally: Terraform and Python skills, with KQL advantageous. Experience securing GitHub/GitHub Actions, Kubernetes and APIs. Strong knowledge of application security testing and vulnerability management. Experience with DevSecOps, threat modelling and security ...

Security Operations Center Analyst

Hiring Organisation
TRIA
Location
Greater Bristol Area, United Kingdom
incidents when required Escalate complex incidents with clear, detailed findings Support incident response, client communications and incident bridges Maintain runbooks, internal documentation and the KQL library Tune detections and manage improvement requests through Azure DevOps What we’re looking for Strong experience in a security operations or analytical role Hands … expertise with Microsoft Defender and Microsoft Sentinel Advanced KQL skills and a strong understanding of Log Analytics Broad knowledge of the Microsoft security stack Strong written and verbal communication skills, including confidence communicating with clients during high-priority incidents Desirable experience Python, Bicep, ARM templates or JSON Microsoft or security ...

Cloud FinOps Analyst

Hiring Organisation
Manufacturing Recruitment Limited
Location
City of London, London, United Kingdom
Employment Type
Permanent
Salary
£50,000
models and platform fundamentals (Azure, Snowflake, Kubecost desirable). Experience with FinOps practices and cost management tools, particularly Kubecost and cloud-native cost portals (KQL desirable). Demonstrated ability to work cross-functionally with Finance and technical teams to support cost visibility and decision-making. ...

Cloud FinOps Analyst

Hiring Organisation
Manufacturing Recruitment Limited
Location
Leicester, Leicestershire, East Midlands, United Kingdom
Employment Type
Permanent
models and platform fundamentals (Azure, Snowflake, Kubecost desirable). Experience with FinOps practices and cost management tools, particularly Kubecost and cloud-native cost portals (KQL desirable). Demonstrated ability to work cross-functionally with Finance and technical teams to support cost visibility and decision-making. ...

Threat Detection Engineer - Hybrid / Remote

Hiring Organisation
Additional Resources
Location
Westminster, City of Westminster, Greater London, United Kingdom
Employment Type
Permanent
Salary
£60000 - £80000/annum
maintain and tune the detection catalogue Build automated reporting dashboards using Microsoft Sentinel workbooks Support security initiatives including ISO 27001 activities and KQL-based tasks Ensure monitoring coverage across cloud platforms, SaaS apps, and internal systems Contribute to documentation of processes, tools, and detection logic What You’ll Bring Must … Have Skills & Experience: Previously worked as a Threat Detection Engineer or in a similar role. Strong proficiency in KQL and hands-on experience with Microsoft Sentinel Familiarity with Microsoft Defender tools (Endpoint & O365) Exposure to Azure cloud logging and Kubernetes environments Knowledge of attacker TTPs and MITRE ATT&CK frameworks ...

Threat Detection Engineer - Hybrid / Remote

Hiring Organisation
Additional Resources Ltd
Location
London, South East, England, United Kingdom
Employment Type
Full-Time
Salary
£60,000 - £80,000 per annum
maintain and tune the detection catalogue Build automated reporting dashboards using Microsoft Sentinel workbooks Support security initiatives including ISO 27001 activities and KQL-based tasks Ensure monitoring coverage across cloud platforms, SaaS apps, and internal systems Contribute to documentation of processes, tools, and detection logic What You’ll Bring Must … Have Skills & Experience: Previously worked as a Threat Detection Engineer or in a similar role. Strong proficiency in KQL and hands-on experience with Microsoft Sentinel Familiarity with Microsoft Defender tools (Endpoint & O365) Exposure to Azure cloud logging and Kubernetes environments Knowledge of attacker TTPs and MITRE ATT&CK frameworks ...

Vulnerability Management Lead (Microsoft Defender TVM)

Hiring Organisation
The Curve Group
Location
City of London, London, United Kingdom
Employment Type
Contract
senior stakeholders. A background in developing or improving vulnerability management strategies, frameworks or operating models. Strong knowledge of Microsoft security technologies. Experience using KQL to interrogate and report on security data. Excellent stakeholder management and communication skills. Previous experience within a regulated environment would be advantageous. ...

Security Engineer (SIEM / XDR) Microsoft Sentinel, Defender - Remote

Hiring Organisation
Nova Source Technologies
Location
United Kingdom
Employment Type
Permanent, Work From Home
Security Engineer (SIEM/XDR) Microsoft Sentinel, Defender, Endpoint, Detection Engineering, Detection-as-Code, KQL, Security Automation, SOAR, Playbooks, Telemetry, Cloud Security, APIs, CI/CD, Infrastructure-as-Code, Python, PowerShell, Windows, Linux, Remote (with UK wide travel) This is an exceptional permanent Security Engineer (SIEM/XDR) opportunity … security engineering or detection engineering experience Hands-on SIEM and XDR tooling Microsoft Sentinel and Microsoft Defender for Endpoint Detection engineering, detection-as-code, KQL, security content and alert logic Automation, SOAR, playbooks, enrichment workflows and response improvement Scripting/programming with Python and/or PowerShell Infrastructure-as-code ...

Graduate SOC Analyst

Hiring Organisation
CyPro
Location
City of London, London, United Kingdom
JIRA Service Management. Detection Engineering Develop and implement new detection rules in Microsoft Sentinel aligned to the MITRE ATT&CK framework. Draft and optimise KQL queries for detection and threat hunting. Refine existing detection logic based on false positive analysis and threat evolution. Threat Intelligence & Enrichment Analyse threat intelligence feeds … hour) of Canary Wharf, London Technical Skills Familiarity with scripting and automation development (you do not need to be fluent in any particular coding language, but you should be able to demonstrate an understanding of how scripting and other tools (such as AI agents) can be used to streamline ...

Senior Detection Engineer (Consultancy)

Hiring Organisation
Fazer Recruitment
Location
Reading, Berkshire, England, United Kingdom
Employment Type
Full-Time
Salary
£85,000 - £90,000 per annum, Negotiable, Inc benefits, OTE
clearance requirement. What you'll be doing Designing and building detection rulesets across SIEM and XDR platforms Writing and tuning detection logic in KQL, cutting false positives without losing coverage Mapping customer log sources against use cases to identify and close coverage gaps Designing use cases aligned to MITRE … workshops, coverage assessments and use case catalogues as customer deliverables What we're looking for Hands-on SIEM engineering experience, ideally Microsoft Sentinel Confident KQL — this is the core of the role SOAR playbook design in Azure Logic Apps, Cortex XSOAR or similar Scripting in Python or PowerShell, and comfort ...

SOC Engineer

Hiring Organisation
4Square Recruitment Ltd
Location
Cambridge, Cambridgeshire, England, United Kingdom
Employment Type
Full-Time
Salary
£40,000 - £80,000 per annum
capability What we’re looking for: Strong SOC/Security Operations experience Hands-on SIEM engineering experience Detection engineering and alert tuning Experience with KQL, SQL or similar query languages Linux experience Threat hunting and incident response experience Scripting/automation using Python and/or PowerShell Exposure ...

SOC Engineer

Hiring Organisation
IBEX RECRUITMENT LTD
Location
North West, United Kingdom
Employment Type
Permanent, Work From Home
Salary
£70,000
Engineering and maintaining Microsoft Sentinel , Defender XDR , and Log Analytics platforms Onboarding and normalising log sources across hybrid/cloud environments Writing and tuning KQL detection rules and analytics logic Building SOAR playbooks (Logic Apps, automation workflows) to reduce manual effort Managing telemetry ingestion, parsers, and data retention for cost … contributing to team development Acting as technical SME during incidents What we're looking for: Deep experience with Microsoft Sentinel , Defender suite , and KQL Strong scripting/automation skills ( PowerShell, Python, Logic Apps ) Solid understanding of MITRE ATT&CK , NCSC CAF , NIST CSF Stakeholder management able to translate technical complexity ...

Senior SOC Engineer

Hiring Organisation
Fazer Recruitment
Location
Cardiff, South Glamorgan, Wales, United Kingdom
Employment Type
Full-Time
Salary
£65,000 - £70,000 per annum, Inc benefits
doing Designing and maintaining the SIEM and XDR platform — data ingestion, log parsing and normalisation, retention, performance Writing and tuning detections in KQL, and building automation to cut manual analyst effort Scripting custom connectors and integrations across the security toolset Leading the technical onboarding of new customers alongside SOC Operations … looking for Around 3–5 years in a Security Operations Centre in an engineering or platform capacity Strong Microsoft Sentinel experience, with confident KQL Hands-on with Microsoft Defender and the wider Microsoft security stack — Intune, Entra ID, Defender for Endpoint Exposure to endpoint tooling such as CrowdStrike, Carbon Black ...