26 to 50 of 93 Kusto Query Language Jobs

Security engineer

Hiring Organisation
Tria
Location
Cardiff, South Glamorgan, United Kingdom
Employment Type
Permanent
Salary
£45000 - £50000/annum
participate in an on-call rota. What we're looking for Strong hands-on experience with Microsoft Defender XDR and Sentinel. Very good KQL and Advanced Hunting skills. Practical experience building, configuring or improving security solutions. Familiarity with DevOps and CI/CD pipelines. Confidence communicating with clients and explaining ...

Azure Platform Architect

Location
Slough, England, United Kingdom
Policy, Management Groups and subscription architecture Azure Migrate and associated discovery tooling Microsoft Defender for Cloud and Microsoft Sentinel Azure Monitor, Log Analytics and KQL Zero Trust architecture High availability and disaster recovery FinOps and cloud cost optimisation Use of GitHub Copilot to accelerate Infrastructure as Code development The Person ...

Security Monitoring & Detection Engineering Lead

Location
Manchester, England, United Kingdom
enterprise environment. A strong record of designing, building, operating and evolving Microsoft Sentinel as a production security monitoring and response capability. Deep expertise in KQL and the engineering of analytics rules, hunting queries, workbooks and threat‐informed detection content. Extensive experience designing telemetry architectures and onboarding security data, including connectors ...

Security Monitoring & Detection Engineering Lead

Location
Greater London, England, United Kingdom
enterprise environment. A strong record of designing, building, operating and evolving Microsoft Sentinel as a production security monitoring and response capability. Deep expertise in KQL and the engineering of analytics rules, hunting queries, workbooks and threat‐informed detection content. Extensive experience designing telemetry architectures and onboarding security data, including connectors ...

Senior Data Platform Engineer

Hiring Organisation
Proactive Appointments
Location
Surrey, United Kingdom
Employment Type
Permanent
Salary
GBP 60,000 - 80,000 Annual
Bicep CI/CD - GitHub Actions and/or Azure DevOps Databricks workspace administration, Unity Catalog & governance Monitoring & observability - Azure Monitor, Log Analytics & KQL Python/PySpark and scalable data pipelines Security, access management, automation and platform operations We're particularly interested in engineers with experience across the broader data ...

Senior Data Platform Engineer

Hiring Organisation
Proactive Appointments
Location
London, United Kingdom
Employment Type
Full-Time
Salary
£60,000 - £80,000 per annum
Bicep CI/CD – GitHub Actions and/or Azure DevOps Databricks workspace administration, Unity Catalog & governance Monitoring & observability – Azure Monitor, Log Analytics & KQL Python/PySpark and scalable data pipelines Security, access management, automation and platform operations We’re particularly interested in engineers with experience across the broader data ...

Lead Threat Detection Engineer

Location
Greater London, England, United Kingdom
than purely responding to SOC alerts Strong SIEM experience – Microsoft Sentinel, Splunk or similar Cloud security experience across AWS, GCP and/or Azure KQL, SPL or similar querying experience Python scripting/security automation Terraform/Infrastructure as Code exposure Experience with threat intelligence or threat hunting Strong ownership ...

Infrastructure Engineer

Location
Manchester, England, United Kingdom
Skill Level LogicMonitor/Monitoring Tools Proficient — alert management, dashboard navigation, threshold tuning Azure Monitor/Log Analytics Awareness to Proficient — alert review, basic KQL queries, VM metrics ServiceNow/Helpdesk Tool Proficient — incident, change, and request management Windows Server (2016/2019/2022) Awareness to Proficient — event logs ...

Senior Security Architect - SecOps and Vulnerability Management

Location
Greater London, England, United Kingdom
advising and influencing enterprise SIEM platforms (e.g., Microsoft Sentinel, Splunk, Chronicle/SecOps). Must be proficient in writing/reviewing advanced detection logic (KQL, SPL, or YARA rules). Deep execution knowledge of generating, managing, and analyzing Software Bills of Materials (SBOMs using frameworks like CycloneDX or SPDX ...

Senior Security Operations Analyst

Location
Leeds, England, United Kingdom
pressured environment and whilst dealing with competing priorities Demonstrable experience with at least one major SIEM and EDR platform, additional hands‐on KQL/SPL, PowerShell/Python experience preferred Demonstrable experience with Security Orchestration and Automation Strong understanding of ITSM workflows, implementing operational processes, and service delivery Practical experience ...

Principal Security Design Consultant

Location
Greater London, England, United Kingdom
500. Hands‐on experience with other SIEM and EDR/XDR platforms such as CrowdStrike, Splunk, QRadar, Rapid7 or Elastic. Experience with KQL, Sigma, Logic Apps, PowerShell or other automation and detection‐as‐code approaches. Knowledge of MITRE ATT&CK, NIST SP 800-61, NCSC CAF and recognised security operations … SIEM, EDR/XDR or protective monitoring transformations. Deep practical design experience with Microsoft Sentinel, Defender XDR and Defender for Endpoint, including Log Analytics, KQL, data connectors, analytics and automation. Full lifecycle delivery experience from discovery and HLD/LLD development through migration, testing, service transition and implementation assurance. Experience ...

Senior Security Engineering Consultant

Hiring Organisation
Matchtech
Location
Basingstoke, Hampshire, UK
Employment Type
Full-time
their SOC functions, tooling, and detection capabilities. Key Responsibilities: Design and deliver detection rulesets across SIEM and XDR platformsDevelop and tune detection logic using KQL or equivalent query languagesDesign detection use cases aligned to MITRE ATT&CK and real-world attack techniquesMap customer log sources to detection use cases … detection outcomesJob Requirements: Strong hands-on experience with SIEM engineering, including developing and tuning detection rules, with Microsoft Sentinel preferredExperience writing detection logic using KQL or similar query languagesProven experience designing and implementing SOAR automations and playbooks such as Logic Apps, Cortex XSOAR or similarScripting and automation capability using ...

Senior Security Engineering Consultant

Hiring Organisation
Infosec
Location
Basingstoke, Hampshire, South East, United Kingdom
Employment Type
Permanent, Work From Home
Salary
£80,000
functions, tooling, and detection capabilities. Key Responsibilities: Design and deliver detection rulesets across SIEM and XDR platforms Develop and tune detection logic using KQL or equivalent query languages Design detection use cases aligned to MITRE ATT&CK and real-world attack techniques Map customer log sources to detection … Requirements: Strong hands-on experience with SIEM engineering, including developing and tuning detection rules, with Microsoft Sentinel preferred Experience writing detection logic using KQL or similar query languages Proven experience designing and implementing SOAR automations and playbooks such as Logic Apps, Cortex XSOAR or similar Scripting and automation capability ...

Senior Security Engineer - Contract

Location
Greater London, England, United Kingdom
security risk clearly to engineering and product audiences. A growth mindset and genuine curiosity to keep learning. SC‐200 (Microsoft Security Operations Analyst) certification. KQL proficiency for detection rule authoring and threat hunting. Experience working in a similar fintech or financial services environment. All are welcome: At Flagstone ...

Incident Response Engineer 2

Location
Oxford, England, United Kingdom
weekends and holidays as part of a rotation Desired: Hands-on experience with EDR, SIEM, and forensic collection tools Familiarity with OSQuery, SQL, or KQL Knowledge of MITRE ATT&CK and incident response frameworks Industry certifications such as GCIH, GCED, CompTIA Security+, or equivalent Experience contributing to playbooks, detection tuning ...

Security Operations Analyst, UK

Hiring Organisation
Anduril Industries
Location
London, UK
Employment Type
Full-time
sourcesExperience in Python development, specifically contributing to a shared codebase used for automating SOC operationsMust have experience with one or more SIEM languages (SPL, KQL, SQL)Experience conducting analysis in a data lake environmentBroad range of practical security knowledge across the spectrum of endpoint, network, identity, application, and cloud infrastructureKnowledge ...

Senior Security Engineering Consultant

Hiring Organisation
Nomios
Location
Basingstoke, Hampshire, UK
Employment Type
Full-time
their detection capabilities. ResponsibilitiesKey responsibilities of the role include: DeliverDesign and deliver detection rulesets across SIEM and XDR platformsDevelop and tune detection logic using KQL or equivalent query languagesDesign detection use cases aligned to MITRE ATT&CK and real-world attack techniquesMap customer log sources to detection use cases … Skills and ExperienceStrong hands-on experience with SIEM engineering, including developing and tuning detection rules, with Microsoft Sentinel preferred Experience writing detection logic using KQL or similar query languages Proven experience designing and implementing SOAR automations and playbooks such as Logic Apps, Cortex XSOAR or similar Scripting and automation ...

IAM Consultant/Developer (Microsoft Entra ID) - Contract role, UK, fully remote

Location
United Kingdom
identity lifecycle automation, ideally via the Microsoft Graph PowerShell SDK. Comfortable working independently and communicating migration risk/status to non-technical stakeholders. Desirable: KQL for log analysis in Microsoft Sentinel or Azure Monitor. Experience with Entra ID B2B/B2C. Background with an alternative IAM platform (ForgeRock, Ping, Okta ...

IAM Consultant/Developer (Microsoft Entra ID) - UK, fully remote

Location
Greater London, England, United Kingdom
identity lifecycle automation, ideally via the Microsoft Graph PowerShell SDK. Comfortable working independently and communicating migration risk/status to non‐technical stakeholders. Desirable: KQL for log analysis in Microsoft Sentinel or Azure Monitor. Experience with Entra ID B2B/B2C. Background with an alternative IAM platform (ForgeRock, Ping, Okta ...

Senior Cyber Security Engineer

Hiring Organisation
Checkout.com
Location
London, UK
Employment Type
Full-time
understanding of security operations workflows: alert triage, incident handling, and vulnerability/finding remediation lifecyclesComfort with scripting to support automation and tooling (e.g. Python, KQL)Experience coordinating remediation across multiple engineering or platform teams, and keeping work moving to closureWorking knowledge of cloud environments (e.g. AWS, Azure ...

Cyber Security Analyst

Hiring Organisation
XACT PLACEMENTS LIMITED
Location
Reading, Berkshire, South East, United Kingdom
Employment Type
Permanent, Work From Home
Salary
£60,000
carry out malware analysis and threat validation. Design, implement and optimise detection content across Microsoft Sentinel, Defender XDR, CrowdStrike and associated platforms, developing advanced KQL queries and analytics rules aligned to MITRE ATT&CK. Act as senior technical owner for security platforms including Microsoft Sentinel, Defender XDR, CrowdStrike Falcon, Entra … Microsoft Defender XDR, CrowdStrike Falcon and associated security technologies. Proven experience in incident response, threat hunting, malware analysis, digital forensics and security investigations. Advanced KQL skills, with the ability to develop and optimise complex detections and threat hunting queries. Strong scripting and automation experience using PowerShell and/or Python ...

3rd Line Security Analyst

Location
Reading, England, United Kingdom
carry out malware analysis and threat validation. Design, implement and optimise detection content across Microsoft Sentinel, Defender XDR, CrowdStrike and associated platforms, developing advanced KQL queries and analytics rules aligned to MITRE ATT&CK. Act as senior technical owner for security platforms including Microsoft Sentinel, Defender XDR, CrowdStrike Falcon, Entra … Microsoft Defender XDR, CrowdStrike Falcon and associated security technologies. Proven experience in incident response, threat hunting, malware analysis, digital forensics and security investigations. Advanced KQL skills, with the ability to develop and optimise complex detections and threat hunting queries. Strong scripting and automation experience using PowerShell and/or Python ...

Senior Security Operations & Threat Hunting Analyst

Location
Leeds, England, United Kingdom
cross-functional teams. You’ll bring 5+ years in Security Operations/Incident Response, strong SIEM/EDR experience, and hands-on skills in KQL/SPL, PowerShell and Python. #J-18808-Ljbffr ...

Hybrid SecOps Engineering Lead: Azure & SOC

Location
Abingdon, England, United Kingdom
lead security operations, detections, and the three-analyst team, troubleshooting issues and guiding engineering teams. Essential experience includes security engineering/operations, Microsoft Sentinel, KQL, incident response on cloud platforms, and IaC with Terraform/Bicep. #J-18808-Ljbffr ...

Identity & Access Security Analyst – Microsoft IAM & Sentinel

Location
West of England, England, United Kingdom
/Azure AD, Conditional Access, MFA and RBAC, with hands-on work in Microsoft Sentinel. You will monitor security events, investigate incidents, write KQL queries, and collaborate with internal teams and third-party security providers to improve the #J-18808-Ljbffr ...