1

Azure Sentinel Kql Jobs in Addison, IL (NOW HIRING)

IAM Lead/Architect

Chicago, IL · On-site

$57 - $78/hr

Awareness of API Management, Firewalls, DLP, VPNs, DNS, Azure Defender, MCAS, Sentinel, WAFs ... KQL/Audit logs etc. * Good understanding of concepts related to docker Security, container ...

Security Administrator

Rosemont, IL · On-site

$100K - $125K/yr

... Azure, Microsoft Entra ID, Microsoft 365, and traditional infrastructure. This is not a policy ... Operate, tune, and build detections in Microsoft Sentinel (KQL for analytics rules, hunting queries ...

Azure Security Consultant

Chicago, IL · On-site

$105K - $160K/yr

... suite, Sentinel, threat hunting * Data Protection : Purview, DLP, Sensitivity Labels, DSPM * Cloud Security : Azure Defender for Cloud, security posture management * Automation & Scripting : KQL ...

Lead Engineer (Azure)

Chicago, IL · On-site +1

$98K - $132K/yr

... suite, Sentinel, threat hunting * Data Protection : Purview, DLP, Sensitivity Labels, DSPM * Cloud Security : Azure Defender for Cloud, security posture management * Automation & Scripting : KQL ...

Senior Cloud Engineer

Chicago, IL · On-site +1

$70K - $144K/yr

Azure Virtual Desktop (AVD) * Plan, deploy, and manage scalable AVD environments in Azure ... Hands-on experience with Log Analytics, KQL, Playbook automation (Logic Apps), and Graph API

Azure Sentinel Kql information

See Addison, IL salary details

$61.1K

$103.2K

$129.2K

How much do azure sentinel kql jobs pay per year?

As of Aug 12, 2026, the average yearly pay for azure sentinel kql in Addison, IL is $103,192.00, according to ZipRecruiter salary data. Most workers in this role earn between $72,600.00 and $122,700.00 per year, depending on experience, location, and employer.

What are some common challenges faced by professionals working with Azure Sentinel KQL, and how can they be addressed?

One common challenge for professionals using Azure Sentinel KQL is efficiently querying and interpreting large volumes of log data while maintaining optimal performance. Navigating the learning curve of KQL syntax and understanding the structure of various data tables can also be complex. To address these challenges, it is helpful to leverage built-in query examples, participate in community forums, and regularly review Microsoft's official documentation for best practices. Collaborating closely with security analysts and IT teams can also streamline the process of creating effective detection rules and incident investigations.

What are the key skills and qualifications needed to thrive as an Azure Sentinel KQL specialist?

To excel as an Azure Sentinel KQL Specialist, you need expertise in security information and event management (SIEM), proficiency in Kusto Query Language (KQL), and a strong understanding of cybersecurity concepts, often supported by certifications like Microsoft Certified: Security Operations Analyst Associate. Familiarity with Azure Sentinel, log analytics workspaces, threat intelligence tools, and incident response platforms is essential. Analytical thinking, attention to detail, and effective communication skills help specialists investigate incidents and convey findings clearly. These skills are vital for efficiently detecting, analyzing, and mitigating security threats in cloud environments.

What is the difference between Azure Sentinel Kql and Security Analyst?

AspectAzure Sentinel KqlSecurity Analyst
Primary RoleWriting queries to analyze security dataMonitoring, investigating, and responding to security incidents
Required SkillsProficiency in Kusto Query Language (KQL), data analysisSecurity best practices, incident response, analytical skills
Work EnvironmentSecurity platforms, cloud environments, data analysis toolsSecurity operations centers, incident response teams
CertificationsAzure certifications, security fundamentalsCompTIA Security+, CISSP, CEH

Azure Sentinel Kql specialists focus on creating and optimizing queries within Azure Sentinel to detect threats, while Security Analysts handle broader security monitoring and incident response. Both roles require security knowledge, but KQL experts are more technical in data analysis, whereas Security Analysts have a wider security scope.

What is Azure Sentinel KQL?

Azure Sentinel KQL refers to the use of Kusto Query Language (KQL) within Microsoft Azure Sentinel, a cloud-native security information and event management (SIEM) solution. KQL is a powerful query language used to search, analyze, and visualize large volumes of data stored in Azure Log Analytics. Security analysts and administrators use KQL in Sentinel to create custom detections, investigate incidents, and build dashboards. Learning KQL is essential for leveraging the full capabilities of Azure Sentinel in threat detection and response.
What cities near Addison, IL are hiring for Azure Sentinel Kql jobs? Cities near Addison, IL with the most Azure Sentinel Kql job openings:
Infographic showing various Azure Sentinel Kql job openings in Addison, IL as of August 2026, with employment types broken down into 86% Full Time, 4% Part Time, and 10% Contract. Highlights an 81% Physical, 6% Hybrid, and 13% Remote job distribution, with an average salary of $103,192 per year, or $49.6 per hour.

IAM Lead/Architect

iTech US, Inc.

Chicago, IL • On-site

$57 - $78/hr

Other

Posted 6 days ago


Job description

IAM Lead/Architect

Chicago, IL

12 months

Job Description:

We are seeking a highly skilled Tech lead/Architect with deeper expertise in various security products, authentication, authorization, access management, AI, governance. As a key member of Workforce Authentication and Authorization team you lead a team to play a vital role in ensuring the secure implementation of various solutions (Hybrid and Cloud).

Requirements/Responsibilities:

  • Lead Identity centric Workforce Security team to develop authentication and access management solutions
  • Drive the development of identity solutions, access patterns, modern security protocols, practicing Zero trust, least privileged, defense in depth principles
  • Good understanding of AI concepts, Patterns and impact on identity and access management domain
  • Participate and engage in AI adoption with Identity focus, knowledge and understanding of Entra ID agentic Identity, authentication flows and Patterns
  • Review and provide feedback on Identity and access management related security solutions proposed by stakeholders and can provide consultation to the partners and IT Management
  • In-depth knowledge and experience on Entra ID, EPM, Sentinel, Azure, AWS Security
  • Knowledge on Okta, PingFederate, Entitlement management solutions
  • Strong knowledge on Identities management on Azure AD with OAuth, OIDC, SAML, SSO, MFA, Conditional access policies, MFA, Kerberos, LDAP, Identity Federations etc.
  • Experience in providing security solutions for Java based Micro services, React based frontends and Android/iOS based mobile applications on the Azure
  • Hands-of experience in JWT, session handling, Code signing, Certificate authentication, TLS/SSL, API Security, Application registration, application integration scenarios etc.
  • Awareness of API Management, Firewalls, DLP, VPNs, DNS, Azure Defender, MCAS, Sentinel, WAFs, Application Gateways, NSGs, App Proxy, Radius clusters, CDN etc.
  • Good understanding of Cloud Infrastructure Entitlement Management solution (CIEM) to ensure smooth remediation of toxic combinations, high risk entitlements etc.
  • Understanding and application of threat modeling concepts and methodologies
  • Understanding of Applications security, OWASP standards, security best practices, browser compatibilities/storages/cookies
  • Acts as Workforce cybersecurity expert to in solutions spanning end user computing, proxy solutions, MFA, SSO, conditional accesses, Password less, Yubikey, bio-metric solutions, identity and governance scenarios, Secrets Management, automation, role based access control, Privileged identity management, Just in time accesses etc.
  • Participates in solutions to support- token handling, OIDC/ OAuth flows, authorization patterns, identity federation, cloud architectures, cryptograpgy, cloud native services, cloud security etc.
  • Deeper understanding on Cloud Security areas such as Policies, RBAC, activities, identities, privileged access management etc
  • Ability to support operations in troubleshooting complex identity scenarios with hands-on experience on Sentinel/KQL/Audit logs etc.
  • Good understanding of concepts related to docker Security, container orchestartions /Kubernetes

Qualifications:

  • Deep knowledge of application or infrastructure systems architecture, usually having experience with multiple system technologies.
  • Good understanding of agentic application architecture and impact of them on IAM domain
  • Excellent consultative and communication skills, and the ability to work effectively with client, partner, and IT management and staff.
  • 10 years of experience in the Information Security role. 5+ Years of experience as an Tech lead
  • CISSP, CSSP, or Cloud security certification preferred
  • Strong collaboration skills and a analytical ability
  • Certifications on Azure, AWS security will be preferred

Education: At least a bachelor s degree (or equivalent experience) in Computer Science, Software Engineering, Electronics Engineering, Information Systems, or a closely related field is required for the project