1

Azure Sentinel Kql Jobs (NOW HIRING)

Partner with Infrastructure teams to harden Windows Server, Windows 11, Azure, and Microsoft 365 ... Experience integrating third-party security platforms into Microsoft Sentinel * KQL development and ...

$85.48 - $125.37/hr

Verstärken Sie unser Team als Cyber Security Consultant - Microsoft Sentinel & Security Operations ... Know‑how in den Bereichen Automatisierung (Playbooks, SOAR), KQL und Azure Monitor * Erfahrung in ...

SIEM Engineer

Wilmington, DE · Remote

$75 - $80/hr

Job Summary Design, deploy, and scale the Microsoft Sentinel and Log Analytics Workspace ... Configure and maintain Data Collection Rules (DCRs) using the Azure Monitor Agent (AMA) to collect ...

... using Azure Sentinel (SIEM), writing and tuning KQL queries for detection rules, alert triage, and threat hunting. - Maintain and execute incident response playbooks specific to AI platforms ...

Showing results 21-40

Azure Sentinel Kql information

See salary details

$61K

$103K

$129K

How much do azure sentinel kql jobs pay per year?

As of Aug 12, 2026, the average yearly pay for azure sentinel kql in the United States is $103,000.00, according to ZipRecruiter salary data. Most workers in this role earn between $72,500.00 and $122,500.00 per year, depending on experience, location, and employer.

What are some common challenges faced by professionals working with Azure Sentinel KQL, and how can they be addressed?

One common challenge for professionals using Azure Sentinel KQL is efficiently querying and interpreting large volumes of log data while maintaining optimal performance. Navigating the learning curve of KQL syntax and understanding the structure of various data tables can also be complex. To address these challenges, it is helpful to leverage built-in query examples, participate in community forums, and regularly review Microsoft's official documentation for best practices. Collaborating closely with security analysts and IT teams can also streamline the process of creating effective detection rules and incident investigations.

What are the key skills and qualifications needed to thrive as an Azure Sentinel KQL specialist?

To excel as an Azure Sentinel KQL Specialist, you need expertise in security information and event management (SIEM), proficiency in Kusto Query Language (KQL), and a strong understanding of cybersecurity concepts, often supported by certifications like Microsoft Certified: Security Operations Analyst Associate. Familiarity with Azure Sentinel, log analytics workspaces, threat intelligence tools, and incident response platforms is essential. Analytical thinking, attention to detail, and effective communication skills help specialists investigate incidents and convey findings clearly. These skills are vital for efficiently detecting, analyzing, and mitigating security threats in cloud environments.

What is the difference between Azure Sentinel Kql and Security Analyst?

AspectAzure Sentinel KqlSecurity Analyst
Primary RoleWriting queries to analyze security dataMonitoring, investigating, and responding to security incidents
Required SkillsProficiency in Kusto Query Language (KQL), data analysisSecurity best practices, incident response, analytical skills
Work EnvironmentSecurity platforms, cloud environments, data analysis toolsSecurity operations centers, incident response teams
CertificationsAzure certifications, security fundamentalsCompTIA Security+, CISSP, CEH

Azure Sentinel Kql specialists focus on creating and optimizing queries within Azure Sentinel to detect threats, while Security Analysts handle broader security monitoring and incident response. Both roles require security knowledge, but KQL experts are more technical in data analysis, whereas Security Analysts have a wider security scope.

What is Azure Sentinel KQL?

Azure Sentinel KQL refers to the use of Kusto Query Language (KQL) within Microsoft Azure Sentinel, a cloud-native security information and event management (SIEM) solution. KQL is a powerful query language used to search, analyze, and visualize large volumes of data stored in Azure Log Analytics. Security analysts and administrators use KQL in Sentinel to create custom detections, investigate incidents, and build dashboards. Learning KQL is essential for leveraging the full capabilities of Azure Sentinel in threat detection and response.
More about Azure Sentinel Kql jobs
What cities are hiring for Azure Sentinel Kql jobs? Cities with the most Azure Sentinel Kql job openings:
What states have the most Azure Sentinel Kql jobs? States with the most job openings for Azure Sentinel Kql jobs include:
Infographic showing various Azure Sentinel Kql job openings in the United States as of August 2026, with employment types broken down into 87% Full Time, 1% Part Time, and 12% Contract. Highlights an 75% Physical, 9% Hybrid, and 16% Remote job distribution, with an average salary of $103,000 per year, or $49.5 per hour.

Senior Cybersecurity Engineer

AeroVironment

Washington, DC • On-site

$111K - $170K/yr

Full-time

Medical, Dental, Vision, Retirement

This job post has expired today. Applications are no longer accepted.


AeroVironment rating

9.1

Company rating: 9.1 out of 10

Based on 7 frontline employees who took The Breakroom Quiz

7th of 72 rated aerospace companies


Job description

Worker Type

Regular


Job Description
 

Summary

The Senior Cyber Security Engineer is a key technical leader within the global Digital Business Technology team, responsible for driving security architecture decisions and providing strategic direction for the organization\'s security posture. This role requires deep expertise across multiple security domains, demonstrated leadership ability, and proven experience in designing and implementing enterprise-scale security solutions across cloud and on-premises environments.

Position Responsibilities:

  • Design, implement, and maintain enterprise cybersecurity solutions across Microsoft technologies.
  • Engineer security controls required for CMMC Level 2/3 and NIST SP 800-171 compliance.
  • Develop and maintain Microsoft Sentinel analytics, workbooks, automation rules, and incident response playbooks.
  • Deploy and manage Microsoft Defender XDR technologies including Defender for Endpoint, Defender for Identity, Defender for Office 365, Defender for Cloud Apps, Microsoft Defender for Cloud
  • Design and administer Microsoft Intune and endpoint security policies.
  • Implement Conditional Access, Identity Protection, and Zero Trust security architectures using Microsoft Entra ID.
  • Build security automation using Logic Apps, Power Automate, KQL, PowerShell, and Microsoft Graph.
  • Develop advanced KQL queries for threat hunting, compliance reporting, and security monitoring.
  • Partner with Infrastructure teams to harden Windows Server, Windows 11, Azure, and Microsoft 365 environments.
  • Support vulnerability management and remediation coordination using tools such as Microsoft Defender Vulnerability Management, Tanium, or similar platforms.
  • Participate in security architecture reviews and provide engineering guidance on new technologies.
  • Support incident response activities during security investigations.
  • Produce technical documentation, standards, and implementation guides.

Basic Qualifications (Required Skills & Experience):

  • Bachelor’s degree in computer science, cyber security, or related STEM field; or equivalent combination of education and experience
  • Minimum 8 – 12 years\' experience in enterprise security engineering, with at least 3 years in a senior technical role
  • Advanced knowledge of security frameworks and compliance standards (NIST, CMMC, DFARS, ITAR)
  • Proven track record of leading large-scale security initiatives and architectural decisions
  • Expert knowledge of Windows, Linux, and MacOS operating systems and enterprise networking concepts
  • Experience leading incident response for critical security events
  • Strong technical writing skills for documentation and policy development
  • Strong scripting experience using PowerShell.
  • Advanced Kusto Query Language (KQL) experience.
  • Experience implementing security baselines and hardening standards.
  • Excellent troubleshooting and analytical skills.
  • Strong written and verbal communication abilities.

Demonstrated experience with:

  • Experience supporting Defense Industrial Base (DIB) organizations
  • Experience in Microsoft GCC High environments
  • Experience with CMMC assessments or audit preparation
  • Experience with Microsoft Purview
  • Experience integrating third-party security platforms into Microsoft Sentinel
  • KQL development and threat hunting
  • Intune enterprise deployments
  • Windows security engineering
  • PowerShell automation
  • Security architecture and Zero Trust implementation

Other Qualifications & Desired Competencies:

  • Master\'s degree in related field preferred
  • Security certifications such as Microsoft Certified: CAE, CISSP, CISM or similar industry standard credentials are highly desired
  • Self-starter capable of leading enterprise security initiatives
  • Strong engineering mindset with an automation-first approach
  • Ability to balance operational needs with regulatory compliance
  • Comfortable working in fast-paced, highly regulated environments
  • Excellent collaborator who can partner across Security, IT, Engineering, and Compliance teams
  • Passion for continuous improvement and emerging cybersecurity technologies

Physical Demands

  • Ability to work in an office environment
  • Required to sit and stand for long periods; talk, hear, and use hands and fingers to operate a computer and telephone keyboard (Frequent)

Special Requirements:

  • U.S. Citizen, U.S. Permanent Resident (Green Card holder) or asylee/refugee status as defined by 8 U.S.C. 1324b(a)(3) required.
  • Occasionally may be required to travel within the Continental U.S.


Clearance Level
 

No Clearance

The salary range for this role is:

$111,500 - $170,000

AeroVironment considers several factors when extending an offer, including but not limited to, the location, the role and associated responsibilities, a candidate’s work experience, education/training, and key skills.

ITAR Requirement:

This position requires access to information that is subject to compliance with the International Traffic Arms Regulations (“ITAR”) and/or the Export Administration Regulations (“EAR”). In order to comply with the requirements of the ITAR and/or the EAR, applicants must qualify as a U.S. person under the ITAR and the EAR, or a person to be approved for an export license by the governing agency whose technology comes under its jurisdiction. Please understand that any job offer that requires approval of an export license will be conditional on AeroVironment’s determination that it will be able to obtain an export license in a time frame consistent with AeroVironment’s business requirements. A “U.S. person” according to the ITAR definition is a U.S. citizen, U.S. lawful permanent resident (green card holder), or protected individual such as a refugee or asylee. See 22 CFR § 120.15. Some positions will require current U.S. Citizenship due to contract requirements.

Benefits:  AV offers an excellent benefits package including medical, dental vision, 401K with company matching, a 9/80 work schedule and a paid holiday shutdown.  For more information about our company benefit offerings please visit:  http://www.avinc.com/myavbenefits.

We also encourage you to review our company website at http://www.avinc.com to learn more about us.

Principals only need apply.  NO agencies please.

About AV:

AV isn’t for everyone. We hire the curious, the relentless, the mission-obsessed. The best of the best.

We don’t just build defense technology—we redefine what’s possible. As the premier autonomous systems company in the U.S., AV delivers breakthrough capabilities across air, land, sea, space, and cyber. From AI-powered drones and loitering munitions to integrated autonomy and space resilience, our technologies shape the future of warfare and protect those who serve.

Founded by legendary innovator Dr. Paul MacCready, AV has spent over 50 years pushing the boundaries of what unmanned systems can do. Our heritage includes seven platforms in the Smithsonian—but we’re not building history, we’re building what’s next.

If you\'re ready to build technology that matters—with speed, scale, and purpose—there’s no better place to do it than AV.

We are proud to be an EEO/AA Equal Opportunity Employer, including disability/veterans. AeroVironment, Inc. is an Equal Employment Opportunity (EEO) employer and welcomes all qualified applicants. Qualified applicants will receive fair and impartial consideration without regard to race, sex, color, religion, national origin, age, disability, protected veteran status, genetic data, sexual orientation, gender identity or other legally protected status.

ITAR

U.S. Citizenship is required. Secret or Top Secret clearance, or the ability obtain a clearance is desired.

What AeroVironment employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom