Azure Sentinel KQL query experience * Threat hunting experience * Digital forensics fundamentals * Experience with classified network monitoring Education: * Bachelor's degree in Computer Science ...
Azure Sentinel KQL query experience * Threat hunting experience * Digital forensics fundamentals * Experience with classified network monitoring Education: * Bachelor's degree in Computer Science ...
CSSP Analyst, Journeyman
Indianapolis, IN ยท On-site
Azure Sentinel KQL query experience * Threat hunting experience * Digital forensics fundamentals * Experience with classified network monitoring Education: * Bachelor's degree in Computer Science ...
CSSP Analyst, Journeyman
Indianapolis, IN ยท On-site
Azure Sentinel KQL query experience * Threat hunting experience * Digital forensics fundamentals * Experience with classified network monitoring Education: * Bachelor's degree in Computer Science ...
Azure Sentinel KQL query experience * Threat hunting experience * Digital forensics fundamentals * Experience with classified network monitoring Education: * Bachelor's degree in Computer Science ...
Azure Sentinel KQL query experience * Threat hunting experience * Digital forensics fundamentals * Experience with classified network monitoring Education: * Bachelor's degree in Computer Science ...
Experience with Azure Sentinel KQL queries * Digital forensics certifications * Experience with classified network monitoring Education: * Bachelor's degree in Computer Science, Engineering ...
Experience with Azure Sentinel KQL queries * Digital forensics certifications * Experience with classified network monitoring Education: * Bachelor's degree in Computer Science, Engineering ...
Experience with Azure Sentinel KQL queries * Digital forensics certifications * Experience with classified network monitoring Education: * Bachelor's degree in Computer Science, Engineering ...
Experience with Azure Sentinel KQL queries * Digital forensics certifications * Experience with classified network monitoring Education: * Bachelor's degree in Computer Science, Engineering ...
CSSP Analyst, Senior
Indianapolis, IN ยท On-site
$91K - $120K/yr
Experience with Azure Sentinel KQL queries * Digital forensics certifications * Experience with classified network monitoring Education: * Bachelor's degree in Computer Science, Engineering ...
CSSP Analyst, Senior
Indianapolis, IN ยท On-site
$91K - $120K/yr
Experience with Azure Sentinel KQL queries * Digital forensics certifications * Experience with classified network monitoring Education: * Bachelor's degree in Computer Science, Engineering ...
You have experience with KQL, Sentinel Workbooks, or similar query/visualization layers in Azure Compensation at Accenture varies depending on a wide array of factors, which may include but are not ...
You have experience with KQL, Sentinel Workbooks, or similar query/visualization layers in Azure Compensation at Accenture varies depending on a wide array of factors, which may include but are not ...
Strong KQL proficiency for threat hunting, detection logic, investigation, and telemetry analysis. Preferred: * MS Sentinel SC-200 badge * SOAR and automation experience, especially with Azure Logic ...
Strong KQL proficiency for threat hunting, detection logic, investigation, and telemetry analysis. Preferred: * MS Sentinel SC-200 badge * SOAR and automation experience, especially with Azure Logic ...
Azure Sentinel Kql information
What are some common challenges faced by professionals working with Azure Sentinel KQL, and how can they be addressed?
What are the key skills and qualifications needed to thrive as an Azure Sentinel KQL specialist?
What is the difference between Azure Sentinel Kql and Security Analyst?
| Aspect | Azure Sentinel Kql | Security Analyst |
|---|---|---|
| Primary Role | Writing queries to analyze security data | Monitoring, investigating, and responding to security incidents |
| Required Skills | Proficiency in Kusto Query Language (KQL), data analysis | Security best practices, incident response, analytical skills |
| Work Environment | Security platforms, cloud environments, data analysis tools | Security operations centers, incident response teams |
| Certifications | Azure certifications, security fundamentals | CompTIA Security+, CISSP, CEH |
Azure Sentinel Kql specialists focus on creating and optimizing queries within Azure Sentinel to detect threats, while Security Analysts handle broader security monitoring and incident response. Both roles require security knowledge, but KQL experts are more technical in data analysis, whereas Security Analysts have a wider security scope.
What is Azure Sentinel KQL?
Full-time
Re-posted 13 days ago
Job description
Overview of position:
We are looking for a CSSP Analyst, Journeyman, to work in Indianapolis, IN.
An active Top-Secret a United States Citizenship is required to be considered for this position.
Responsibilities
- Provide 24/7 security monitoring and analysis for DFAS CCE (ON-SITE REQUIRED)
- Monitor security events using Azure Sentinel, ArcSight, and other SIEM tools
- Perform initial triage and classification of security incidents
- Analyze phishing and spam emails, reviewing headers, attachments, and URLs for malicious indicators
- Validate and classify incidents, determining true positives and escalating when required
- Draft incident summaries and analyst reports for leadership and case records
- Keep investigation notes and case records updated
- Support protocol monitoring achieving 100% documentation per DFAS CSIRP
- Participate in threat hunting activities under senior guidance
- Operate CSSP toolsets for unclassified and classified enclaves
Experience/Skills:
- 5+ years cybersecurity/SOC analyst experience
- Security+ certification
- DoD 8140 Cyber Defensive Analyst (Intermediate) Playlist qualification
- Experience with SIEM tools (Azure Sentinel, ArcSight, Splunk)
- Knowledge of phishing analysis and email security
- Incident triage and classification experience
- Understanding of network security monitoring
- Familiarity with DFAS CSIRP or similar incident response procedures
- Experience with ticketing systems for incident tracking
Preferred Qualifications:
- CySA+ certification (upgrade path)
- Experience with DFAS CSSP operations
- Prior 24/7 SOC shift experience
- Azure Sentinel KQL query experience
- Threat hunting experience
- Digital forensics fundamentals
- Experience with classified network monitoring
Education:
- Bachelor's degree in Computer Science, Engineering, Information Technology, or a related field
Certifications:
- Cyber Defensive Analyst (Intermediate) Playlist
- CompTIA Security+
Clearance:
- Active Top-Secret clearance is required.
- Must be a United States Citizen and pass a background check.
- Maintain applicable security clearance(s) at the level required by the client and/or applicable certification(s) as requested by FEDITC and/or required by FEDITC'S Client(s)/Customer(s)/Prime contractor(s).
FEDITC, LLC. is committed to fostering an inclusive workplace and provides equal employment opportunities (EEO) to all employees and applicants for employment. We do not employ AI tools in our decision-making processes. Regardless of race, color, religion, sex (including pregnancy), sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status, amnesty, or status as a covered veteran, FEDITC, LLC. ensures that all employment decisions are made in accordance with applicable federal, state, and local laws. Our commitment to non-discrimination in employment extends to every location in which our company operates.