Microsoft Sentinel ... Azure Log Analytics * Kusto Query Language (KQL) * Azure Logic Apps * Microsoft Defender XDR
Microsoft Sentinel ... Azure Log Analytics * Kusto Query Language (KQL) * Azure Logic Apps * Microsoft Defender XDR
Microsoft Sentinel ... Azure Log Analytics * Kusto Query Language (KQL) * Azure Logic Apps * Microsoft Defender XDR
Microsoft Sentinel ... Azure Log Analytics * Kusto Query Language (KQL) * Azure Logic Apps * Microsoft Defender XDR
Microsoft Sentinel ... Azure Log Analytics * Kusto Query Language (KQL) * Azure Logic Apps * Microsoft Defender XDR
Microsoft Sentinel ... Azure Log Analytics * Kusto Query Language (KQL) * Azure Logic Apps * Microsoft Defender XDR
Microsoft Sentinel ... Azure Log Analytics * Kusto Query Language (KQL) * Azure Logic Apps * Microsoft Defender XDR
Microsoft Sentinel ... Azure Log Analytics * Kusto Query Language (KQL) * Azure Logic Apps * Microsoft Defender XDR
Microsoft Sentinel ... Azure Log Analytics * Kusto Query Language (KQL) * Azure Logic Apps * Microsoft Defender XDR
Microsoft Sentinel ... Azure Log Analytics * Kusto Query Language (KQL) * Azure Logic Apps * Microsoft Defender XDR
Microsoft Sentinel ... Azure Log Analytics * Kusto Query Language (KQL) * Azure Logic Apps * Microsoft Defender XDR
Microsoft Sentinel ... Azure Log Analytics * Kusto Query Language (KQL) * Azure Logic Apps * Microsoft Defender XDR
Microsoft Sentinel ... Azure Log Analytics * Kusto Query Language (KQL) * Azure Logic Apps * Microsoft Defender XDR
Microsoft Sentinel ... Azure Log Analytics * Kusto Query Language (KQL) * Azure Logic Apps * Microsoft Defender XDR
Microsoft Sentinel ... Azure Log Analytics * Kusto Query Language (KQL) * Azure Logic Apps * Microsoft Defender XDR
Microsoft Sentinel ... Azure Log Analytics * Kusto Query Language (KQL) * Azure Logic Apps * Microsoft Defender XDR
Microsoft Sentinel ... Azure Log Analytics * Kusto Query Language (KQL) * Azure Logic Apps * Microsoft Defender XDR
Microsoft Sentinel ... Azure Log Analytics * Kusto Query Language (KQL) * Azure Logic Apps * Microsoft Defender XDR
Senior Architect - Cloud Platform
$66.50 - $84.75/hr
... KQL), Application Insights, Azure Site Recovery, Azure Backup, Security Center, Azure Networking (App Gateways, Front Door, Firewall, VWAN), Azure Storage, Azure Automation, Azure Sentinel, App ...
Senior Architect - Cloud Platform
$66.50 - $84.75/hr
... KQL), Application Insights, Azure Site Recovery, Azure Backup, Security Center, Azure Networking (App Gateways, Front Door, Firewall, VWAN), Azure Storage, Azure Automation, Azure Sentinel, App ...
... KQL queries for Sentinel to improve detection fidelity and reduce false positives. • Tune ... monitoring (Azure, AWS) • Certifications such as GIAC GCIA, GCED, or Microsoft Security ...
... KQL queries for Sentinel to improve detection fidelity and reduce false positives. • Tune ... monitoring (Azure, AWS) • Certifications such as GIAC GCIA, GCED, or Microsoft Security ...
Detection Engineer
Arlington, VA · On-site
... KQL queries for Sentinel to improve detection fidelity and reduce false positives. • Tune ... monitoring (Azure, AWS) • Certifications such as GIAC GCIA, GCED, or Microsoft Security ...
Detection Engineer
Arlington, VA · On-site
... KQL queries for Sentinel to improve detection fidelity and reduce false positives. • Tune ... monitoring (Azure, AWS) • Certifications such as GIAC GCIA, GCED, or Microsoft Security ...
Detection Engineer
Arlington, VA · On-site
... KQL queries for Sentinel to improve detection fidelity and reduce false positives. • Tune ... monitoring (Azure, AWS) • Certifications such as GIAC GCIA, GCED, or Microsoft Security ...
Detection Engineer
Arlington, VA · On-site
... KQL queries for Sentinel to improve detection fidelity and reduce false positives. • Tune ... monitoring (Azure, AWS) • Certifications such as GIAC GCIA, GCED, or Microsoft Security ...
Engagement Lead - Azure
$60 - $78.25/hr
Hands\-on experience with automation and scripting, including PowerShell, KQL, ARM\/Bicep ... Familiarity with Microsoft Defender suite and Microsoft Sentinel, with experience designing and ...
Engagement Lead - Azure
$60 - $78.25/hr
Hands\-on experience with automation and scripting, including PowerShell, KQL, ARM\/Bicep ... Familiarity with Microsoft Defender suite and Microsoft Sentinel, with experience designing and ...
IT - Consultant - Infrastructure Management | Enterprise Mobility Solution | MS Azure AD, MS Azure R
Pittsburgh, PA · On-site
$61.75 - $80.25/hr
... Sentinel (SIEM), Identity Monitoring, Audit & Compliance, Azure Policy, Management Groups, Managed Identities, Azure AD-based admin configs, Azure Monitor, Log Analytics (KQL) Secrets Management ...
IT - Consultant - Infrastructure Management | Enterprise Mobility Solution | MS Azure AD, MS Azure R
Pittsburgh, PA · On-site
$61.75 - $80.25/hr
... Sentinel (SIEM), Identity Monitoring, Audit & Compliance, Azure Policy, Management Groups, Managed Identities, Azure AD-based admin configs, Azure Monitor, Log Analytics (KQL) Secrets Management ...
Cybersecurity Lead
Houston, TX · On-site
... Sentinel (KQL, analyticsrules, SOAR playbooks) and Defender XDR suite Lead threat detection ... Skills Azure Security Center KQL Logic Apps / SOAR MS Graph API Lighthouse (Multi-tenant ...
Cybersecurity Lead
Houston, TX · On-site
... Sentinel (KQL, analyticsrules, SOAR playbooks) and Defender XDR suite Lead threat detection ... Skills Azure Security Center KQL Logic Apps / SOAR MS Graph API Lighthouse (Multi-tenant ...
Awareness of API Management| Firewalls| DLP| VPNs| DNS| Azure Defender| MCAS| Sentinel| WAFs ... KQL/Audit logs etc.Good understanding of concepts related to docker Security| container ...
Awareness of API Management| Firewalls| DLP| VPNs| DNS| Azure Defender| MCAS| Sentinel| WAFs ... KQL/Audit logs etc.Good understanding of concepts related to docker Security| container ...
Microsoft Sentinel Subject Matter Expert
Marietta, GA · On-site
$62 - $82.50/hr
... Azure Log Analytics. - Develop and tune KQL queries, analytics rules, alerts, and security ... Sentinel experience.
Quick apply
Microsoft Sentinel Subject Matter Expert
Marietta, GA · On-site
$62 - $82.50/hr
... Azure Log Analytics. - Develop and tune KQL queries, analytics rules, alerts, and security ... Sentinel experience.
IAM Lead/Architect
Chicago, IL · On-site
$57 - $78/hr
Awareness of API Management, Firewalls, DLP, VPNs, DNS, Azure Defender, MCAS, Sentinel, WAFs ... KQL/Audit logs etc. * Good understanding of concepts related to docker Security, container ...
IAM Lead/Architect
Chicago, IL · On-site
$57 - $78/hr
Awareness of API Management, Firewalls, DLP, VPNs, DNS, Azure Defender, MCAS, Sentinel, WAFs ... KQL/Audit logs etc. * Good understanding of concepts related to docker Security, container ...
Hands-on experience with MS Sentinel (Azure Sentinel), including: * Creating, tuning, and maintaining analytics rules, workbooks, and dashboards. * Writing advanced Kusto Query Language (KQL) queries ...
Hands-on experience with MS Sentinel (Azure Sentinel), including: * Creating, tuning, and maintaining analytics rules, workbooks, and dashboards. * Writing advanced Kusto Query Language (KQL) queries ...
Azure Sentinel Kql information
See salary details
$61K - $67.2K
8% of jobs
$72.8K is the 25th percentile. Wages below this are outliers.
$67.2K - $73.4K
19% of jobs
$73.4K - $79.5K
4% of jobs
$79.5K - $85.7K
4% of jobs
$85.7K - $91.9K
0% of jobs
$91.9K - $98.1K
0% of jobs
$98.1K - $104.3K
0% of jobs
$104.3K - $110.5K
1% of jobs
The median wage is $113.7K / yr.
$110.5K - $116.6K
27% of jobs
$121.2K is the 75th percentile. Wages above this are outliers.
$116.6K - $122.8K
16% of jobs
$122.8K - $129K
21% of jobs
$61K
$103K
$129K
How much do azure sentinel kql jobs pay per year?
What is Azure Sentinel KQL?
What are the key skills and qualifications needed to thrive as an Azure Sentinel KQL specialist?
What are some common challenges faced by professionals working with Azure Sentinel KQL, and how can they be addressed?
What is the difference between Azure Sentinel Kql and Security Analyst?
| Aspect | Azure Sentinel Kql | Security Analyst |
|---|---|---|
| Primary Role | Writing queries to analyze security data | Monitoring, investigating, and responding to security incidents |
| Required Skills | Proficiency in Kusto Query Language (KQL), data analysis | Security best practices, incident response, analytical skills |
| Work Environment | Security platforms, cloud environments, data analysis tools | Security operations centers, incident response teams |
| Certifications | Azure certifications, security fundamentals | CompTIA Security+, CISSP, CEH |
Azure Sentinel Kql specialists focus on creating and optimizing queries within Azure Sentinel to detect threats, while Security Analysts handle broader security monitoring and incident response. Both roles require security knowledge, but KQL experts are more technical in data analysis, whereas Security Analysts have a wider security scope.
What cities are hiring for Azure Sentinel Kql jobs?
Cities with the most Azure Sentinel Kql job openings:
What states have the most Azure Sentinel Kql jobs?
States with the most job openings for Azure Sentinel Kql jobs include:
What job categories do people searching Azure Sentinel Kql jobs look for?
The top searched job categories for Azure Sentinel Kql jobs are:

Full-time
This job post has expired today. Applications are no longer accepted.
Job description
We are seeking an experienced Microsoft Sentinel Subject Matter Expert (SME) to design, implement, optimize, and manage Microsoft Sentinel and Azure security solutions. The role will focus on SIEM/SOAR engineering, threat detection, incident response, security automation, cloud security, and compliance across enterprise Azure environments.
Roles and Responsibilities- Design, implement, configure, and manage Microsoft Sentinel SIEM/SOAR solutions.
- Integrate security data sources into Azure Log Analytics, including Syslog, CEF, APIs, and threat intelligence feeds.
- Develop, optimize, and maintain KQL queries, analytics rules, detection rules, alerts, workbooks, and dashboards.
- Develop automated security response workflows using Azure Logic Apps and Microsoft Copilot for Security.
- Perform threat hunting, incident investigation, detection engineering, and response activities in collaboration with SOC teams.
- Implement and manage Azure security controls aligned with Zero Trust principles.
- Configure and secure enterprise Azure environments, including identity, access, monitoring, and security services.
- Assess vulnerabilities, analyze attacker TTPs, and support remediation and security improvement initiatives.
- Integrate and manage Microsoft Defender XDR, including Defender for Endpoint, Office 365, Identity, and Cloud Apps.
- Support cloud security governance, compliance, risk assessments, and audit activities.
- Provide technical guidance on security architecture, SIEM/SOAR strategy, detection engineering, and cloud security initiatives.
- Develop security standards, operational procedures, and best practices for Sentinel and Azure security services.
- Collaborate with Security Operations, Cloud Engineering, Identity, Application Security, and Governance teams.
- Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related field.
- 5+ years of cybersecurity experience, including strong hands-on experience with Microsoft Sentinel engineering and administration.
- Strong expertise in:
- Microsoft Sentinel
- Azure Log Analytics
- Kusto Query Language (KQL)
- Azure Logic Apps
- Microsoft Defender XDR
- Azure Security and Identity Services
- Microsoft Entra ID
- Privileged Identity Management (PIM)
- Conditional Access
- Security monitoring and incident response
- CI/CD security and application security scanning
- Strong understanding of SIEM/SOAR, threat detection, threat hunting, incident response, and security automation.
- Experience implementing security controls in enterprise Azure environments.
- Strong knowledge of Zero Trust architecture and cloud security best practices.
- Experience with Azure Government / Government Cloud environments.
- Experience with FISMA, FedRAMP, and NIST security and compliance frameworks.
- Relevant certifications such as CISSP, CCSP, Microsoft Certified: Azure Security Engineer Associate, or Microsoft Certified: Cybersecurity Architect Expert.
- Experience working with security auditors, compliance teams, and executive stakeholders.
About 2T Consulting
Sourced by ZipRecruiter
Industry
It services
Company size
51 - 200 Employees
Headquarters location
Edison, NJ, US