1

Azure Sentinel Kql Jobs in Indiana (NOW HIRING)

CSSP Analyst, Senior

Indianapolis, IN ยท On-site

$91K - $120K/yr

Experience with Azure Sentinel KQL queries * Digital forensics certifications * Experience with classified network monitoring Education: * Bachelor's degree in Computer Science, Engineering ...

Azure Sentinel Kql information

What are some common challenges faced by professionals working with Azure Sentinel KQL, and how can they be addressed?

One common challenge for professionals using Azure Sentinel KQL is efficiently querying and interpreting large volumes of log data while maintaining optimal performance. Navigating the learning curve of KQL syntax and understanding the structure of various data tables can also be complex. To address these challenges, it is helpful to leverage built-in query examples, participate in community forums, and regularly review Microsoft's official documentation for best practices. Collaborating closely with security analysts and IT teams can also streamline the process of creating effective detection rules and incident investigations.

What are the key skills and qualifications needed to thrive as an Azure Sentinel KQL specialist?

To excel as an Azure Sentinel KQL Specialist, you need expertise in security information and event management (SIEM), proficiency in Kusto Query Language (KQL), and a strong understanding of cybersecurity concepts, often supported by certifications like Microsoft Certified: Security Operations Analyst Associate. Familiarity with Azure Sentinel, log analytics workspaces, threat intelligence tools, and incident response platforms is essential. Analytical thinking, attention to detail, and effective communication skills help specialists investigate incidents and convey findings clearly. These skills are vital for efficiently detecting, analyzing, and mitigating security threats in cloud environments.

What is the difference between Azure Sentinel Kql and Security Analyst?

AspectAzure Sentinel KqlSecurity Analyst
Primary RoleWriting queries to analyze security dataMonitoring, investigating, and responding to security incidents
Required SkillsProficiency in Kusto Query Language (KQL), data analysisSecurity best practices, incident response, analytical skills
Work EnvironmentSecurity platforms, cloud environments, data analysis toolsSecurity operations centers, incident response teams
CertificationsAzure certifications, security fundamentalsCompTIA Security+, CISSP, CEH

Azure Sentinel Kql specialists focus on creating and optimizing queries within Azure Sentinel to detect threats, while Security Analysts handle broader security monitoring and incident response. Both roles require security knowledge, but KQL experts are more technical in data analysis, whereas Security Analysts have a wider security scope.

What is Azure Sentinel KQL?

Azure Sentinel KQL refers to the use of Kusto Query Language (KQL) within Microsoft Azure Sentinel, a cloud-native security information and event management (SIEM) solution. KQL is a powerful query language used to search, analyze, and visualize large volumes of data stored in Azure Log Analytics. Security analysts and administrators use KQL in Sentinel to create custom detections, investigate incidents, and build dashboards. Learning KQL is essential for leveraging the full capabilities of Azure Sentinel in threat detection and response.
What are popular job titles related to Azure Sentinel Kql jobs in Indiana? For Azure Sentinel Kql jobs in Indiana, the most frequently searched job titles are:
What cities in Indiana are hiring for Azure Sentinel Kql jobs? Cities in Indiana with the most Azure Sentinel Kql job openings:

CSSP Analyst, Journeyman P47- P55

FEDITC LLC

Indianapolis, IN โ€ข On-site

Full-time

Re-posted 13 days ago


Job description

FEDITC, LLC is a fast-growing business supporting DoD and other intelligence agencies worldwide. FEDITC develops mission critical national security systems throughout the world directly supporting the Warfighter, DoD Leadership, & the country. We are proud & honored to provide these services.
Overview of position:
We are looking for a CSSP Analyst, Journeyman, to work in Indianapolis, IN.
An active Top-Secret a United States Citizenship is required to be considered for this position.
Responsibilities
  • Provide 24/7 security monitoring and analysis for DFAS CCE (ON-SITE REQUIRED)
  • Monitor security events using Azure Sentinel, ArcSight, and other SIEM tools
  • Perform initial triage and classification of security incidents
  • Analyze phishing and spam emails, reviewing headers, attachments, and URLs for malicious indicators
  • Validate and classify incidents, determining true positives and escalating when required
  • Draft incident summaries and analyst reports for leadership and case records
  • Keep investigation notes and case records updated
  • Support protocol monitoring achieving 100% documentation per DFAS CSIRP
  • Participate in threat hunting activities under senior guidance
  • Operate CSSP toolsets for unclassified and classified enclaves

Experience/Skills:
  • 5+ years cybersecurity/SOC analyst experience
  • Security+ certification
  • DoD 8140 Cyber Defensive Analyst (Intermediate) Playlist qualification
  • Experience with SIEM tools (Azure Sentinel, ArcSight, Splunk)
  • Knowledge of phishing analysis and email security
  • Incident triage and classification experience
  • Understanding of network security monitoring
  • Familiarity with DFAS CSIRP or similar incident response procedures
  • Experience with ticketing systems for incident tracking

Preferred Qualifications:
  • CySA+ certification (upgrade path)
  • Experience with DFAS CSSP operations
  • Prior 24/7 SOC shift experience
  • Azure Sentinel KQL query experience
  • Threat hunting experience
  • Digital forensics fundamentals
  • Experience with classified network monitoring

Education:
  • Bachelor's degree in Computer Science, Engineering, Information Technology, or a related field

Certifications:
  • Cyber Defensive Analyst (Intermediate) Playlist
  • CompTIA Security+

Clearance:
  • Active Top-Secret clearance is required.
  • Must be a United States Citizen and pass a background check.
  • Maintain applicable security clearance(s) at the level required by the client and/or applicable certification(s) as requested by FEDITC and/or required by FEDITC'S Client(s)/Customer(s)/Prime contractor(s).

FEDITC, LLC. is committed to fostering an inclusive workplace and provides equal employment opportunities (EEO) to all employees and applicants for employment. We do not employ AI tools in our decision-making processes. Regardless of race, color, religion, sex (including pregnancy), sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status, amnesty, or status as a covered veteran, FEDITC, LLC. ensures that all employment decisions are made in accordance with applicable federal, state, and local laws. Our commitment to non-discrimination in employment extends to every location in which our company operates.