1

Azure Sentinel Kql Jobs in Indiana (NOW HIRING)

CSSP Analyst, Senior

Indianapolis, IN · On-site

$91K - $120K/yr

Experience with Azure Sentinel KQL queries * Digital forensics certifications * Experience with classified network monitoring Education: * Bachelor's degree in Computer Science, Engineering ...

Azure Sentinel Kql information

What is Azure Sentinel KQL?

Azure Sentinel KQL refers to the use of Kusto Query Language (KQL) within Microsoft Azure Sentinel, a cloud-native security information and event management (SIEM) solution. KQL is a powerful query language used to search, analyze, and visualize large volumes of data stored in Azure Log Analytics. Security analysts and administrators use KQL in Sentinel to create custom detections, investigate incidents, and build dashboards. Learning KQL is essential for leveraging the full capabilities of Azure Sentinel in threat detection and response.

What are the key skills and qualifications needed to thrive as an Azure Sentinel KQL specialist?

To excel as an Azure Sentinel KQL Specialist, you need expertise in security information and event management (SIEM), proficiency in Kusto Query Language (KQL), and a strong understanding of cybersecurity concepts, often supported by certifications like Microsoft Certified: Security Operations Analyst Associate. Familiarity with Azure Sentinel, log analytics workspaces, threat intelligence tools, and incident response platforms is essential. Analytical thinking, attention to detail, and effective communication skills help specialists investigate incidents and convey findings clearly. These skills are vital for efficiently detecting, analyzing, and mitigating security threats in cloud environments.

What are some common challenges faced by professionals working with Azure Sentinel KQL, and how can they be addressed?

One common challenge for professionals using Azure Sentinel KQL is efficiently querying and interpreting large volumes of log data while maintaining optimal performance. Navigating the learning curve of KQL syntax and understanding the structure of various data tables can also be complex. To address these challenges, it is helpful to leverage built-in query examples, participate in community forums, and regularly review Microsoft's official documentation for best practices. Collaborating closely with security analysts and IT teams can also streamline the process of creating effective detection rules and incident investigations.

What is the difference between Azure Sentinel Kql and Security Analyst?

AspectAzure Sentinel KqlSecurity Analyst
Primary RoleWriting queries to analyze security dataMonitoring, investigating, and responding to security incidents
Required SkillsProficiency in Kusto Query Language (KQL), data analysisSecurity best practices, incident response, analytical skills
Work EnvironmentSecurity platforms, cloud environments, data analysis toolsSecurity operations centers, incident response teams
CertificationsAzure certifications, security fundamentalsCompTIA Security+, CISSP, CEH

Azure Sentinel Kql specialists focus on creating and optimizing queries within Azure Sentinel to detect threats, while Security Analysts handle broader security monitoring and incident response. Both roles require security knowledge, but KQL experts are more technical in data analysis, whereas Security Analysts have a wider security scope.

What are popular job titles related to Azure Sentinel Kql jobs in Indiana?

For Azure Sentinel Kql jobs in Indiana, the most frequently searched job titles are:

What job categories do people searching Azure Sentinel Kql jobs in Indiana look for?

The top searched job categories for Azure Sentinel Kql jobs in Indiana are:

What cities in Indiana are hiring for Azure Sentinel Kql jobs?

Cities in Indiana with the most Azure Sentinel Kql job openings:

CSSP Analyst, Journeyman

ITI Solutions, Inc

Indianapolis, IN • On-site

Full-time

Re-posted 6 days ago


Job description

ITI Solutions is a fast-growing business supporting DoD and other intelligence agencies worldwide. ITI Solutions develops mission critical national security systems throughout the world directly supporting the Warfighter, DoD Leadership, & the country. We are proud & honored to provide these services.

About ITI Solutions, Inc.

ITI Solutions, Inc.  is a Service-Disabled Veteran-Owned Small Business (SDVOSB) with a strong track record supporting Department of Defense (DoD) programs, including U.S. Army vehicle production, sustainment, and modernization efforts.

Founded by a Service-Disabled Veteran, we bring mission-driven expertise in engineering support, logistics coordination, and program execution to critical national defense initiatives.

As an Equal Opportunity Employer, ITI Solutions is committed to fostering a diverse, inclusive, and respectful workplace. We do not discriminate in employment decisions on the basis of race, color, religion, national origin, sex, gender, gender identity, sexual orientation, age, disability, protected veteran status, genetic information, or any other characteristic protected by applicable federal, state, or local law. We are dedicated to providing equal employment opportunities to all applicants and employees and maintaining a work environment that is free from discrimination and harassment.

Overview of position:

We are looking for a CSSP Analyst, Journeyman, to work in Indianapolis, IN.

An active Top-Secret a United States Citizenship is required to be considered for this position.

Responsibilities

  • Provide 24/7 security monitoring and analysis for DFAS CCE (ON-SITE REQUIRED)
  • Monitor security events using Azure Sentinel, ArcSight, and other SIEM tools
  • Perform initial triage and classification of security incidents
  • Analyze phishing and spam emails, reviewing headers, attachments, and URLs for malicious indicators
  • Validate and classify incidents, determining true positives and escalating when required
  • Draft incident summaries and analyst reports for leadership and case records
  • Keep investigation notes and case records updated
  • Support protocol monitoring achieving 100% documentation per DFAS CSIRP
  • Participate in threat hunting activities under senior guidance
  • Operate CSSP toolsets for unclassified and classified enclaves

Experience/Skills:

  • 5+ years cybersecurity/SOC analyst experience
  • Security+ certification
  • DoD 8140 Cyber Defensive Analyst (Intermediate) Playlist qualification
  • Experience with SIEM tools (Azure Sentinel, ArcSight, Splunk)
  • Knowledge of phishing analysis and email security
  • Incident triage and classification experience
  • Understanding of network security monitoring
  • Familiarity with DFAS CSIRP or similar incident response procedures
  • Experience with ticketing systems for incident tracking

Preferred Qualifications:

  • CySA+ certification (upgrade path)
  • Experience with DFAS CSSP operations
  •  Prior 24/7 SOC shift experience
  • Azure Sentinel KQL query experience
  • Threat hunting experience
  • Digital forensics fundamentals
  • Experience with classified network monitoring

Education:

  • Bachelor’s degree in Computer Science, Engineering, Information Technology, or a related field

Certifications:

  • Cyber Defensive Analyst (Intermediate) Playlist
  • CompTIA Security+

Clearance:

  • Active Top-Secret clearance is required.
  • Must be a United States Citizen and pass a background check.