... using Sentinel playbooks, Log Analytics, and KQL queries • Conduct security reviews of ... Azure Security Engineer Associate (AZ-500), Microsoft Cybersecurity Architect (SC-100) • ...
... using Sentinel playbooks, Log Analytics, and KQL queries • Conduct security reviews of ... Azure Security Engineer Associate (AZ-500), Microsoft Cybersecurity Architect (SC-100) • ...
... using Sentinel playbooks, Log Analytics, and KQL queries • Conduct security reviews of ... Azure Security Engineer Associate (AZ-500), Microsoft Cybersecurity Architect (SC-100) • ...
... using Sentinel playbooks, Log Analytics, and KQL queries • Conduct security reviews of ... Azure Security Engineer Associate (AZ-500), Microsoft Cybersecurity Architect (SC-100) • ...
... and deploys Sentinel SOAR automation playbooks using Azure Logic Apps, Azure Functions, ARM ... KQL). · Builds and maintains analytics content, data parsers, normalization rules, and entity ...
Quick apply
... and deploys Sentinel SOAR automation playbooks using Azure Logic Apps, Azure Functions, ARM ... KQL). · Builds and maintains analytics content, data parsers, normalization rules, and entity ...
Security Engineer - Azure Government
Palo Alto, CA · Hybrid
$180K - $440K/yr
We are seeking a skilled Azure Security Engineer to design, implement, and maintain robust security ... using Sentinel playbooks, Log Analytics, and KQL queries * Conduct security reviews of ...
Security Engineer - Azure Government
Palo Alto, CA · Hybrid
$180K - $440K/yr
We are seeking a skilled Azure Security Engineer to design, implement, and maintain robust security ... using Sentinel playbooks, Log Analytics, and KQL queries * Conduct security reviews of ...
We are seeking a skilled Azure Security Engineer to design, implement, and maintain robust security ... using Sentinel playbooks, Log Analytics, and KQL queries * Conduct security reviews of ...
We are seeking a skilled Azure Security Engineer to design, implement, and maintain robust security ... using Sentinel playbooks, Log Analytics, and KQL queries * Conduct security reviews of ...
We are seeking a skilled Azure Security Engineer to design, implement, and maintain robust security ... using Sentinel playbooks, Log Analytics, and KQL queries * Conduct security reviews of ...
Quick apply
We are seeking a skilled Azure Security Engineer to design, implement, and maintain robust security ... using Sentinel playbooks, Log Analytics, and KQL queries * Conduct security reviews of ...
We are seeking a skilled Azure Security Engineer to design, implement, and maintain robust security ... using Sentinel playbooks, Log Analytics, and KQL queries * Conduct security reviews of ...
Quick apply
We are seeking a skilled Azure Security Engineer to design, implement, and maintain robust security ... using Sentinel playbooks, Log Analytics, and KQL queries * Conduct security reviews of ...
Senior Cloud Security Engineer - Cleared (Polygraph)
Reston, VA · On-site
$119K - $163K/yr
... Sentinel, Azure Monitoring, and security threat detection/analysis. • Strong knowledge of KQL to develop security reports, dashboards, and detection rules. • Solid understanding of Zero Trust ...
Senior Cloud Security Engineer - Cleared (Polygraph)
Reston, VA · On-site
$119K - $163K/yr
... Sentinel, Azure Monitoring, and security threat detection/analysis. • Strong knowledge of KQL to develop security reports, dashboards, and detection rules. • Solid understanding of Zero Trust ...
... Sentinel, Azure Monitor, and cloud threat detection and analysis. • Advanced knowledge of KQL for building security dashboards, alerts, and detection rules. • Solid understanding of Zero Trust ...
... Sentinel, Azure Monitor, and cloud threat detection and analysis. • Advanced knowledge of KQL for building security dashboards, alerts, and detection rules. • Solid understanding of Zero Trust ...
Linux Systems Administrator (Azure Based)
North Logan, UT · On-site
$72K - $156K/yr
Familiarity with Microsoft Sentinel and KQL for log analysis * Experience with PKI solutions such ... Prior experience supporting Linux endpoints in enterprise Azure GCC High environments * Hands-on ...
Linux Systems Administrator (Azure Based)
North Logan, UT · On-site
$72K - $156K/yr
Familiarity with Microsoft Sentinel and KQL for log analysis * Experience with PKI solutions such ... Prior experience supporting Linux endpoints in enterprise Azure GCC High environments * Hands-on ...
Linux Systems Administrator (Azure Based)
Logan, UT · On-site
$72K - $156K/yr
Familiarity with Microsoft Sentinel and KQL for log analysis * Experience with PKI solutions such ... Prior experience supporting Linux endpoints in enterprise Azure GCC High environments * Hands-on ...
Quick apply
Linux Systems Administrator (Azure Based)
Logan, UT · On-site
$72K - $156K/yr
Familiarity with Microsoft Sentinel and KQL for log analysis * Experience with PKI solutions such ... Prior experience supporting Linux endpoints in enterprise Azure GCC High environments * Hands-on ...
... Sentinel Security Orchestration and Automated Response (SOAR) frameworks and playbooks for ... KQL), Splunk Programming Language (SPL), Yara rules, Tanium Signal Language, PowerShell, VBS ...
... Sentinel Security Orchestration and Automated Response (SOAR) frameworks and playbooks for ... KQL), Splunk Programming Language (SPL), Yara rules, Tanium Signal Language, PowerShell, VBS ...
CMMC Security Engineer (Hybrid)
Las Vegas, NV · Remote
$120K - $170K/yr
Deploy and configure Microsoft Sentinel: Log Analytics workspace setup, data connector deployment (M365, Entra ID, Defender, Azure Activity, Firewall, NSG flow logs), KQL-based analytics rules ...
Quick apply
CMMC Security Engineer (Hybrid)
Las Vegas, NV · Remote
$120K - $170K/yr
Deploy and configure Microsoft Sentinel: Log Analytics workspace setup, data connector deployment (M365, Entra ID, Defender, Azure Activity, Firewall, NSG flow logs), KQL-based analytics rules ...
Senior Cloud Security Engineer - Cleared (Polygraph)
$119K - $163K/yr
Expertise with Microsoft Sentinel, Azure Monitoring, and security threat detection/analysis. Strong knowledge of KQL to develop security reports, dashboards, and detection rules. Solid understanding ...
Senior Cloud Security Engineer - Cleared (Polygraph)
$119K - $163K/yr
Expertise with Microsoft Sentinel, Azure Monitoring, and security threat detection/analysis. Strong knowledge of KQL to develop security reports, dashboards, and detection rules. Solid understanding ...
IT Security Engineer (L3)
Charleston, WV · Remote
$105K - $125K/yr
Microsoft Sentinel: KQL, data connectors, analytics rules, workbook authoring, cost management ... Azure VM and Docker Compose administration * SharePoint Online administration and Viva Connections
IT Security Engineer (L3)
Charleston, WV · Remote
$105K - $125K/yr
Microsoft Sentinel: KQL, data connectors, analytics rules, workbook authoring, cost management ... Azure VM and Docker Compose administration * SharePoint Online administration and Viva Connections
Deploy and configure Microsoft Sentinel: Log Analytics workspace setup, data connector deployment (M365, Entra ID, Defender, Azure Activity, Firewall, NSG flow logs), KQL-based analytics rules ...
Quick apply
Deploy and configure Microsoft Sentinel: Log Analytics workspace setup, data connector deployment (M365, Entra ID, Defender, Azure Activity, Firewall, NSG flow logs), KQL-based analytics rules ...
IT Security Engineer (L3)
Charleston, WV · Remote
$105K - $125K/yr
Microsoft Sentinel: KQL, data connectors, analytics rules, workbook authoring, cost management ... Azure VM and Docker Compose administration * SharePoint Online administration and Viva Connections
IT Security Engineer (L3)
Charleston, WV · Remote
$105K - $125K/yr
Microsoft Sentinel: KQL, data connectors, analytics rules, workbook authoring, cost management ... Azure VM and Docker Compose administration * SharePoint Online administration and Viva Connections
Senior Cloud Security Engineer - Cleared (Polygraph)
Reston, VA · On-site
$119K - $163K/yr
... Sentinel, Azure Monitoring, and security threat detection/analysis. · Strong knowledge of KQL to develop security reports, dashboards, and detection rules. · Solid understanding of Zero Trust ...
Quick apply
Senior Cloud Security Engineer - Cleared (Polygraph)
Reston, VA · On-site
$119K - $163K/yr
... Sentinel, Azure Monitoring, and security threat detection/analysis. · Strong knowledge of KQL to develop security reports, dashboards, and detection rules. · Solid understanding of Zero Trust ...
Senior Cloud Security Engineer - Cleared (Polygraph)
Reston, VA · On-site
$119K - $163K/yr
... Sentinel, Azure Monitoring, and security threat detection/analysis. • Strong knowledge of KQL to develop security reports, dashboards, and detection rules. • Solid understanding of Zero Trust ...
Senior Cloud Security Engineer - Cleared (Polygraph)
Reston, VA · On-site
$119K - $163K/yr
... Sentinel, Azure Monitoring, and security threat detection/analysis. • Strong knowledge of KQL to develop security reports, dashboards, and detection rules. • Solid understanding of Zero Trust ...
CMMC Security Engineer (Hybrid)
Las Vegas, NV · Hybrid
$120K - $170K/yr
Deploy and configure Microsoft Sentinel: Log Analytics workspace setup, data connector deployment (M365, Entra ID, Defender, Azure Activity, Firewall, NSG flow logs), KQL-based analytics rules ...
Quick apply
CMMC Security Engineer (Hybrid)
Las Vegas, NV · Hybrid
$120K - $170K/yr
Deploy and configure Microsoft Sentinel: Log Analytics workspace setup, data connector deployment (M365, Entra ID, Defender, Azure Activity, Firewall, NSG flow logs), KQL-based analytics rules ...
Azure Sentinel Kql information
See salary details
$61K - $67.2K
8% of jobs
$72.8K is the 25th percentile. Wages below this are outliers.
$67.2K - $73.4K
19% of jobs
$73.4K - $79.5K
4% of jobs
$79.5K - $85.7K
4% of jobs
$85.7K - $91.9K
0% of jobs
$91.9K - $98.1K
0% of jobs
$98.1K - $104.3K
0% of jobs
$104.3K - $110.5K
1% of jobs
The median wage is $113.7K / yr.
$110.5K - $116.6K
27% of jobs
$121.2K is the 75th percentile. Wages above this are outliers.
$116.6K - $122.8K
16% of jobs
$122.8K - $129K
21% of jobs
$61K
$103K
$129K
How much do azure sentinel kql jobs pay per year?
What are some common challenges faced by professionals working with Azure Sentinel KQL, and how can they be addressed?
What are the key skills and qualifications needed to thrive as an Azure Sentinel KQL Specialist, and why are they important?
What is the difference between Azure Sentinel Kql and Security Analyst?
| Aspect | Azure Sentinel Kql | Security Analyst |
|---|---|---|
| Primary Role | Writing queries to analyze security data | Monitoring, investigating, and responding to security incidents |
| Required Skills | Proficiency in Kusto Query Language (KQL), data analysis | Security best practices, incident response, analytical skills |
| Work Environment | Security platforms, cloud environments, data analysis tools | Security operations centers, incident response teams |
| Certifications | Azure certifications, security fundamentals | CompTIA Security+, CISSP, CEH |
Azure Sentinel Kql specialists focus on creating and optimizing queries within Azure Sentinel to detect threats, while Security Analysts handle broader security monitoring and incident response. Both roles require security knowledge, but KQL experts are more technical in data analysis, whereas Security Analysts have a wider security scope.
What is Azure Sentinel KQL?
- Vice President Cloud Cyber Security
- Vice President Ot Cyber Security
- Vice President Cyber Security Governance
- Vice President Corporate Sustainability
- Vice President Resilience Planner
- Vice President Soar Engineer
- Vice President Of Information Technology
- Vice President Ciso
- Grc Director
- Vice President Oim Offshore

Full-time
Posted 27 days ago
Job description
xAI is a company focused on creating AI systems to aid humanity in its pursuit of knowledge. They are seeking a skilled Azure Security Engineer to design, implement, and maintain security controls across their Azure Gov Cloud environment, ensuring compliance with government regulations and collaborating with various teams to embed security throughout the development lifecycle.
Responsibilities:
• Implement, design, and manage security architecture for Azure Government and Commercial deployments (with considerations for DoD IL5\IL6 and FedRAMP High controls)
• Configure and optimize Microsoft Defender for Cloud, Microsoft Sentinel, Microsoft Defender for Endpoint, and related services for threat detection, vulnerability management, and automated response
• Design and enforce identity & access management using Microsoft Entra ID, Privileged Identity Management (PIM), Conditional Access policies, RBAC, and just-in-time access
• Secure network architectures with Azure Firewall, Network Security Groups (NSGs), DDoS Protection, Web Application Firewall (WAF), Network Watcher, and private endpoints
• Protect data at rest and in transit via Azure Key Vault, encryption strategies, data classification, and information protection controls
• Develop and maintain security policies, initiatives, and blueprints using Azure Policy and Microsoft Purview for compliance (NIST, FedRAMP, CMMC, STIGs, etc.)
• Perform threat hunting, incident response, and forensics using Sentinel playbooks, Log Analytics, and KQL queries
• Conduct security reviews of Infrastructure as Code (IaC), containers, Kubernetes (AKS), and serverless workloads
• Collaborate with developers and architects to implement DevSecOps practices, including secure CI/CD pipelines, code scanning, and secure defaults
• Monitor and remediate security findings, reduce attack surface, and improve overall security posture per the Microsoft Cloud Security Benchmark (MCSB)
• Deploy configurations and compliance policies to Azure AVD endpoints using Intune and other Azure native services.
Qualifications:
Required:
• Active U.S. security clearance (e.g., Secret, Top Secret) or eligibility to obtain one.
• 3+ years of experience in cloud security, cybersecurity engineering, or related roles (with strong Azure focus)
• Deep hands-on expertise with core Azure security services: Microsoft Defender suite, Sentinel, Intune, Entra ID, Key Vault, Azure Policy, Firewall, Network Watcher, and Purview
• Strong understanding of DLP implementation both in cloud and on endpoints utilizing Purview and other Microsoft native controls
• Experience implementing security in hybrid/multi-cloud environments
• Proficiency in scripting/automation (PowerShell, Azure CLI, Bicep/ARM templates, Terraform)
• Strong understanding of identity federation, zero-trust principles, encryption, network security, and vulnerability management
• Familiarity with compliance frameworks (NIST, FedRAMP, CMMC, STIGs, etc.) and regulatory requirements
• Excellent problem-solving, analytical, and communication skills
• Strong verbal and written communication skills and the ability to stay composed under pressure.
Preferred:
• Microsoft Certified: Azure Security Engineer Associate (AZ-500), Microsoft Cybersecurity Architect (SC-100)
• Additional relevant certifications (e.g., CISSP, CCSP, Microsoft Certified: Azure Administrator, AWS Security Specialty, SANS GCPS, SANS GCAD)
• Deep experience with detection and response engineering and SOC operations
• Knowledge of container security (Docker, AKS), secure DevOps, or AI/ML workload protection
• Prior experience in government regulations frameworks such as FedRAMP and CMMC.
Company:
XAI is an artificial intelligence startup that develops AI solutions and tools to enhance reasoning and search capabilities. It is a sub-organization of SpaceX. Founded in 2023, the company is headquartered in Palo Alto, USA, with a team of 1001-5000 employees. The company is currently Late Stage.