51 to 75 of 93 Kusto Query Language Jobs

Security Analyst

Location
Greater London, England, United Kingdom
Required Proven experience in Security Operations or Cyber Security. Hands‐on experience with Splunk, log forwarding and SIEM administration. Strong analytical skills using SPL, KQL and/or SQL. Experience investigating security incidents, insider threats or data exfiltration. Knowledge of vulnerability management and security assurance within enterprise environments. #J ...

Senior Security Operations Analyst

Hiring Organisation
DGH Recruitment
Location
Leeds, West Yorkshire, Yorkshire, United Kingdom
Employment Type
Permanent
Salary
£90,000
triage, threat hunting, data loss prevention, and operational risk analysis. * Demonstrable experience with at least one major SIEM and EDR platform, additional hands on KQL/SPL, PowerShell/Python experience preferred. * Demonstrable experience with Security Orchestration and Automation. * Certifications such as SC-200, AZ-500, GCIA/GCIH/ ...

Performance and Monitoring Engineer

Hiring Organisation
Solus Accident Repair Centres
Location
Birchanger, Hertfordshire, United Kingdom
Employment Type
Permanent
Salary
GBP 40,000 - 50,000 Annual
Analytics, Defender for Cloud) Excellent understanding of cloud performance, IaaS/PaaS, networking fundamentals, API performance and capacity modelling Skilled in dashboards, log queries (KQL), custom metrics and performance analysis Ability to diagnose complex issues across infrastructure, networks, applications or databases Confident scripting and automation skills (PowerShell, Azure Automation, Graph ...

Performance and Monitoring Engineer

Hiring Organisation
Solus Accident Repair Centres
Location
Stansted, Essex, South East, United Kingdom
Employment Type
Permanent
Salary
£50,000
Analytics, Defender for Cloud) Excellent understanding of cloud performance, IaaS/PaaS, networking fundamentals, API performance and capacity modelling Skilled in dashboards, log queries (KQL), custom metrics and performance analysis Ability to diagnose complex issues across infrastructure, networks, applications or databases Confident scripting and automation skills (PowerShell, Azure Automation, Graph ...

Senior Detection & Threat Engineer

Hiring Organisation
Checkout.com
Location
London, UK
Employment Type
Full-time
intrusion techniques across the attack lifecycleHands-on experience buidling detection logic in modern SIEM platforms (e.g Sentinel)Proficienty with scripting and programmaining (e.g. Python, KQL) to build detection pipelines and automationWillingness to challenge bad detections, weak assumptions, and vanity metricsPragmatic mindset: precision and impact beat coverage theatreExperience operating beyond traditional ...

Application Security / DevSecOps Engineer - Central or Eastern time, US or Canada

Location
Boston, England, United Kingdom
management tools such as GitHub Advanced Security, Tenable, or similar. Knowledge of API, web application, and software supply chain security (SBOM) Familiarity with major language frameworks such as C#, Java, React, or Python. Awareness of security considerations for AI/ML integrations, such as risks like prompt injection Familiarity … fundamentals and network security concepts. Proficiency in at least one scripting or programming language such as Python, PowerShell, JavaScript, or Go. Familiarity with KQL or similar query languages is preferred. Knowledge & Frameworks Understanding of common cybersecurity threats, attack techniques, and defensive controls. Familiarity with the MITRE ...

Cloud Support Engineer

Location
United Kingdom
Please note that for this role, you must be based in the UK, Malta, Bulgaria or Portugal. About Us Ascent has recently been acquired by Acuity Analytics , marking an exciting new chapter for our business ...

Senior Microsoft Security Architect: Azure & Sentinel

Location
Basildon, England, United Kingdom
Sentinel, Defender XDR and Microsoft Purview, delivering scalable security solutions and improving detection coverage. The role requires hands-on experience with Sentinel analytics using KQL, Defender XDR capabilities, Azure security controls and IAM with Entra ID. #J-18808-Ljbffr ...

Microsoft Security Engineer

Location
Basildon, England, United Kingdom
security controls. Key Responsibilities Design, implement and optimise Microsoft Sentinel environments, including onboarding, configuration and continuous improvement Develop and tune Sentinel analytics rules using KQL, improving detection coverage and reducing false positives Support security monitoring, threat detection and incident investigation across enterprise environments Configure and enhance Microsoft Defender XDR capabilities … produce security documentation, recommendations and implementation plans Required Experience Strong commercial experience within Microsoft security engineering roles Hands-on experience with Microsoft Sentinel, including KQL, detection engineering and SIEM optimisation Strong knowledge of Microsoft Defender XDR security capabilities Experience with Microsoft Purview DLP, sensitivity labels and information protection Strong understanding ...

24/7 SOC Analyst

Location
Basingstoke, England, United Kingdom
Experience with Microsoft Sentinel, Google SecOps or other SIEM platforms. Experience with Defender, CrowdStrike, SentinelOne or other XDR solutions. Ability to query in KQL, CQL, S1QL, XQL or similar languages. Awareness of threat intelligence concepts and application to investigations. Awareness of coding or scripting, with proficiency in at least … language preferred (but not required). Job Specifics Location: This role is home‐based with occasional visits to the office in Basingstoke Hours: 12‐hour shifts: 2 days, 2 nights; 4 days/nights off. Flexibility with hours will be required in the event of a major incident Security ...

Senior SOC Analyst

Location
England, United Kingdom
confirm investigation workflows and expected outcomes. Analyse attacker tactics, techniques and procedures (TTPs) and ensure detection content remains aligned with emerging threats. Utilise KQL, SPL, SQL, log analysis, event correlation, and telemetry investigation to validate detection's and support investigations. Support continuous improvement of detection and response capabilities. Stakeholder Management … understanding of attacker tactics, techniques and procedures (TTPs). Experience mapping detections to recognised threat frameworks such as MITRE ATT&CK . Experience using KQL, SPL, SQL , or similar query languages for investigation, threat hunting, and alert validation. Ability to define escalation criteria and investigation workflows. Experience working across ...

Cyber Operations Security Engineer

Location
Manchester, England, United Kingdom
across the platforms in use and surrounding technical practices Deliver end‐to‐end SIEM/Sentinel engineering by onboarding customers, configuring data connectors, integrations, KQL, automation, dashboards and reporting. Implement tuning, enrichment and optimisation across Sentinel and align with other SIEM tools. Maintain SIEM ingestion pipeline reliability by investigating ...

Security Consultant

Location
Greater London, England, United Kingdom
delivering detection engineering engagements, including: Designing and implementing high-quality detection rules across SIEM and XDR platforms. Creating and optimising detection logic using KQL and other query languages. Developing detection use cases aligned with the MITRE ATT&CK framework and current threat techniques. Assessing customer telemetry and identifying opportunities … complex problems and working closely with customers. You’ll ideally have experience with: SIEM engineering, preferably Microsoft Sentinel. Detection engineering and rule development using KQL or similar languages. SOAR platforms such as Microsoft Logic Apps, Cortex XSOAR or equivalent. Python, PowerShell or other scripting languages for automation and API integration. ...

SecOps Engineering Lead

Location
Abingdon, England, United Kingdom
health, ingestion and cost management, retention, and integration with Defender XDR, Defender for Cloud and Entra ID Protection. Own detection engineering: write and tune KQL analytics rules and hunting queries, map coverage to MITRE ATT&CK, track false‐positive rates, and retire rules that no longer earn their place. Automate … mentoring analysts. Hands‐on Microsoft Sentinel administration: workspace design, data connectors and ingestion cost control, retention, workbooks, automation rules and Logic Apps playbooks. Strong KQL and detection engineering: you can write, tune and defend an analytics rule mapped to MITRE ATT&CK, and explain why it fires ...

Security Detection & Response Specialist

Location
Chester, England, United Kingdom
experience with log analysis and telemetry interpretation, including familiarity with querying or analyzing data using tools such as SIEM platforms or query languages (KQL, SPL, SQL, or similar) Exposure to security platforms and technologies such as SIEM, EDR/XDR, identity systems, or cloud environments Foundational understanding of common ...

Security Detection & Response II

Hiring Organisation
Bank of America
Location
Chester, Cheshire, UK
Employment Type
Full-time
positives. Considerable proficiency in log analysis, telemetry interpretation, and cross-system data correlation, including the ability to query, manipulate, and optimize data using KQL, SPL, SQL, or similar languages for investigative and detection use casesPractical experience with containment, response actions, and automation, including developing or maintaining SOAR workflows ...

Remote UK: Threat Detection Content Engineer

Location
United Kingdom
candidates will have 5-8 years in detection engineering or related roles, with deep expertise in Microsoft Sentinel, 365 Defender, Logic Apps, and strong KQL skills. #J-18808-Ljbffr ...

Cyber Security Operations Lead

Hiring Organisation
Sanderson Recruitment
Location
South West, United Kingdom
Employment Type
Contract
Contract Rate
£550 - £575 per day
Cyber Security Operations - 6 months - Umbrella - 2 days on site in Head Office per week - £550/£575 Sentinel/Defender XDR and KQL proficient Able to pick up new tooling Outstanding communication skills Nice to haves but not essential Proofpoint, Tenable, Secure web gateway, purview. Role is monitor ...

Cloud FinOps Analyst

Location
Tonbridge, England, United Kingdom
models and platform fundamentals (Azure, Snowflake, Kubecost desirable). Experience with FinOps practices and cost management tools, particularly Kubecost and cloud‐native cost portals (KQL desirable). Demonstrated ability to work cross‐functionally with Finance and technical teams to support cost visibility and decision‐making #J-18808-Ljbffr ...

Cloud FinOps Analyst

Hiring Organisation
Manufacturing Recruitment Limited
Location
City of London, London, United Kingdom
Employment Type
Permanent
Salary
£60,000
models and platform fundamentals (Azure, Snowflake, Kubecost desirable). Experience with FinOps practices and cost management tools, particularly Kubecost and cloud-native cost portals (KQL desirable). Demonstrated ability to work cross-functionally with Finance and technical teams to support cost visibility and decision-making. ...

Security Engineering Consultant (Detection Engineering / Microsoft Sentinel)

Hiring Organisation
Fazer Recruitment
Location
London, South East England, United Kingdom
Employment Type
Full-Time
Salary
£80,000 - £85,000 per annum
detection as code" approach, so detections and automations are built consistently and at scale. What you'll do Build and tune detection rulesets in KQL (or equivalent) across SIEM and XDR platforms Design use cases aligned to MITRE ATT&CK and assess coverage against customer log sources Develop SOAR automations … clear deliverables such as detection strategies, use case catalogues and coverage assessments What you'll bring Strong SIEM engineering experience, ideally Microsoft Sentinel Proven KQL detection writing SOAR experience (Logic Apps, Cortex XSOAR or similar) Python or PowerShell scripting, including API integration XDR/EDR experience (Defender, CrowdStrike, Cortex ...

SR. CYBERSECURITY ENGINEER, CLOUD AND INCIDENT RESPONSE

Hiring Organisation
Widenet Consulting
Location
Seattle, Washington, United States
Employment Type
Permanent
Salary
USD Hourly
signal quality and cost efficiency, including connector selection, ingestion tiering, and table-level retention decisions - Author and maintain analytic rules and hunting queries in KQL - Map detection coverage to MITRE ATT&CK and close identified gaps - Reduce false positive volume and improve alert enrichment and automation through SOAR playbooks Data … experience: Sentinel, Defender XDR, Defender for Cloud, Entra ID, Intune - Direct, demonstrable Microsoft Purview experience across DLP, sensitivity labels, and Insider Risk Management - Strong KQL authoring ability, including detection development and investigative hunting - Demonstrated incident response leadership on real incidents, not tabletop only - Azure cloud security depth, including identity, networking ...

Senior SOC Analyst (Outside IR35)

Location
West Midlands, England, United Kingdom
encryption. Ability to think critically under pressure and respond effectively to fast-moving security incidents. Scripting or query experience is highly desirable (SPL, KQL, etc.). Good communication skills from previous roles. Due to the nature and urgency of this post, candidates holding or who have held high level ...

SIEM Engineer

Location
Reading, England, United Kingdom
Microsoft Sentinel, ensuring reliable and comprehensive security telemetry. Develop custom parsers and data transformations to normalise and enrich ingested data, and design and optimise KQL queries to support effective threat detection, monitoring and security investigations. Key skills and responsibilities, Integrate and onboard log sources into Microsoft Sentinel, ensuring reliable security … telemetry. Develop custom parsers, data transformations and KQL queries for threat detection and investigation. Create and maintain analytic rules and detection logic aligned to emerging threats and business requirements. Develop Logic Apps and SOAR workflows to automate security response. Implement CI/CD pipelines using Azure DevOps/ ...

Senior Cyber Security Analyst

Hiring Organisation
Tria Recruitment
Location
London, UK
Employment Type
Full-time
industry best practice. Detection Engineering & Security AutomationConfigure, optimise and continuously improve Microsoft Sentinel and Microsoft Defender technologies. Develop and tune detection logic using KQL to identify emerging threats and attacker behaviours. Build and maintain automated SOAR workflows using Logic Apps and related technologies. Integrate Microsoft security tooling with third-party … Experience managing stakeholder communications during high-severity incidents. Strong understanding of attacker tactics, techniques and procedures (TTPs).Technical SkillsStrong Microsoft security ecosystem expertise. Advanced KQL experience for investigations, detections and reporting. Experience building automation workflows using Logic Apps or similar technologies. Knowledge of cloud security principles across Azure and ideally ...