1

Azure Sentinel Kql Jobs in Oregon (NOW HIRING)

Azure Sentinel Kql information

What is Azure Sentinel KQL?

Azure Sentinel KQL refers to the use of Kusto Query Language (KQL) within Microsoft Azure Sentinel, a cloud-native security information and event management (SIEM) solution. KQL is a powerful query language used to search, analyze, and visualize large volumes of data stored in Azure Log Analytics. Security analysts and administrators use KQL in Sentinel to create custom detections, investigate incidents, and build dashboards. Learning KQL is essential for leveraging the full capabilities of Azure Sentinel in threat detection and response.

What are the key skills and qualifications needed to thrive as an Azure Sentinel KQL specialist?

To excel as an Azure Sentinel KQL Specialist, you need expertise in security information and event management (SIEM), proficiency in Kusto Query Language (KQL), and a strong understanding of cybersecurity concepts, often supported by certifications like Microsoft Certified: Security Operations Analyst Associate. Familiarity with Azure Sentinel, log analytics workspaces, threat intelligence tools, and incident response platforms is essential. Analytical thinking, attention to detail, and effective communication skills help specialists investigate incidents and convey findings clearly. These skills are vital for efficiently detecting, analyzing, and mitigating security threats in cloud environments.

What are some common challenges faced by professionals working with Azure Sentinel KQL, and how can they be addressed?

One common challenge for professionals using Azure Sentinel KQL is efficiently querying and interpreting large volumes of log data while maintaining optimal performance. Navigating the learning curve of KQL syntax and understanding the structure of various data tables can also be complex. To address these challenges, it is helpful to leverage built-in query examples, participate in community forums, and regularly review Microsoft's official documentation for best practices. Collaborating closely with security analysts and IT teams can also streamline the process of creating effective detection rules and incident investigations.

What is the difference between Azure Sentinel Kql and Security Analyst?

AspectAzure Sentinel KqlSecurity Analyst
Primary RoleWriting queries to analyze security dataMonitoring, investigating, and responding to security incidents
Required SkillsProficiency in Kusto Query Language (KQL), data analysisSecurity best practices, incident response, analytical skills
Work EnvironmentSecurity platforms, cloud environments, data analysis toolsSecurity operations centers, incident response teams
CertificationsAzure certifications, security fundamentalsCompTIA Security+, CISSP, CEH

Azure Sentinel Kql specialists focus on creating and optimizing queries within Azure Sentinel to detect threats, while Security Analysts handle broader security monitoring and incident response. Both roles require security knowledge, but KQL experts are more technical in data analysis, whereas Security Analysts have a wider security scope.

Information Security Risk Analyst

Lam Research Corporation

Tualatin, OR • On-site

Full-time

Re-posted 2 days ago


Lam Research rating

8.2

Company rating: 8.2 out of 10

Based on 46 frontline employees who took The Breakroom Quiz

134th of 499 rated machine equipment manufacturers


Job description

Job Summary
The Cyber Threat Analytics Analyst is responsible for identifying, developing, and improving the organization's ability to detect malicious behavior, suspicious activity, and security anomalies across the enterprise. This role is part Information Security team focused on bringing detection development, threat analysis operationalization, SIEM correlation, behavioral analytics, and AI-assisted threat detection capabilities into the organization.The analyst will work closely with Security Operations, Incident Response, and Vulnerability Management teams to improve detection coverage, reduce false positives, and identify threats that may bypass traditional controls.
Job Responsibilities
  • Develop, test, tune, and maintain SIEM detection rules, log correlation searches, alerts, dashboards, and analytics.
  • Translate threat intelligence, adversary tactics, and emerging attack trends into actionable detections.
  • Build and improve analytics to identify malicious behavior, compromised accounts, lateral movement, and anomalous activity.
  • Use AI-driven analytics, UEBA, and behavioral baselining to identify activity that deviates from normal user, endpoint, network, cloud, and application behavior.
  • Map detection content to MITRE ATT&CK tactics and techniques to identify coverage strengths and gaps.
  • Partner with SOC analysts to improve alert triage, investigation playbooks, enrichment, and escalation criteria.
  • Support Incident Response during active investigations by analyzing logs, identifying patterns, and developing new detections from lessons learned.
  • Identify gaps in logging, telemetry, and visibility and recommend improvements to security monitoring coverage.
  • Document detection logic, assumptions, data sources, expected behavior, response guidance, and tuning decisions.
  • Track detection effectiveness, alert fidelity, false positive rates, detection coverage, and time-to-detect improvements.

Who We're Looking For
We are looking for an analytical and curious cybersecurity professional who enjoys finding patterns in large volumes of security data. The ideal candidate understands how attackers operate, how enterprise systems generate security telemetry, and how to turn threat intelligence into meaningful detections. The right person for this role should be comfortable working across SIEM data, endpoint telemetry, identity logs, cloud activity, email security events, network data, and behavioral analytics platforms. They should be able to think like an attacker, understand normal business behavior, and identify signals that indicate suspicious or malicious activity.
Strong candidates will have experience in one or more of the following areas:
  • Security Operations Center analysis
  • Threat hunting
  • SIEM rule development
  • Threat intelligence analysis
  • Incident response
  • Detection tuning
  • Behavioral analytics or UEBA
  • Cloud, endpoint, identity, or network security monitoring

Preferred Qualifications
  • Experience with SIEM platforms such as Microsoft Sentinel, Splunk, Exabeam, Securonix, or similar tools.
  • Experience writing detection queries using KQL, SPL, SQL, or similar query languages.
  • Familiarity with Microsoft Defender XDR, Defender for Endpoint, Defender for Identity, Microsoft Sentinel, Entra ID, or similar security platforms.
  • Understanding of MITRE ATT&CK and common adversary tactics, techniques, and procedures.
  • Experience using threat intelligence to create detections and threat hunting hypotheses.
  • Experience with AI-assisted analytics, UEBA, anomaly detection, or behavioral baselining.
  • Familiarity with cloud security monitoring across Azure, AWS, or Google Cloud.
  • Ability to analyze logs from identity systems, endpoints, firewalls, proxies, email gateways, SaaS applications, and cloud platforms.
  • Experience documenting detection logic, investigation steps, and response guidance.
  • Scripting or automation experience with Python, PowerShell, Logic Apps, or similar tools.
  • Familiarity with MISP, STIX/TAXII, threat intelligence feeds, or indicator management.
  • Certifications such as GCIH, GCIA, GCDA, GMON, GCTI, GCFA, Security+, CySA+, CISSP, or equivalent experience.

Our commitment
We believe it is important for every person to feel valued, included, and empowered to achieve their full potential. By bringing unique individuals and viewpoints together, we achieve extraordinary results.
Lam Research ("Lam" or the "Company") is an equal opportunity employer. Lam is committed to and reaffirms support of equal opportunity in employment and non-discrimination in employment policies, practices and procedures on the basis of race, religious creed, color, national origin, ancestry, physical disability, mental disability, medical condition, genetic information, marital status, sex (including pregnancy, childbirth and related medical conditions), gender, gender identity, gender expression, age, sexual orientation, or military and veteran status or any other category protected by applicable federal, state, or local laws. It is the Company's intention to comply with all applicable laws and regulations. Company policy prohibits unlawful discrimination against applicants or employees.
Lam offers a variety of work location models based on the needs of each role. Our hybrid roles combine the benefits of on-site collaboration with colleagues and the flexibility to work remotely and fall into two categories - On-site Flex and Virtual Flex. 'On-site Flex' you'll work 3+ days per week on-site at a Lam or customer/supplier location, with the opportunity to work remotely for the balance of the week. 'Virtual Flex' you'll work 1-2 days per week on-site at a Lam or customer/supplier location, and remotely the rest of the time.
Our Perks and Benefits
At Lam, our people make amazing things possible. That's why we invest in you throughout the phases of your life with a comprehensive set of outstanding benefits.

What Lam Research employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


Lam Research logo

About Lam Research

Sourced by ZipRecruiter

Lam Research designs and builds products for semiconductor manufacturing, including equipment for thin film deposition, plasma etch, photoresist strip, and wafer cleaning processes.

Industry

Manufacturing

Company size

10,000+ Employees

Headquarters location

Fremont, CA, US

Year founded

1980

Social media