1

Azure Sentinel Kql Jobs (NOW HIRING)

... using Azure Sentinel (SIEM), writing and tuning KQL queries for detection rules, alert triage, and threat hunting. - Maintain and execute incident response playbooks specific to AI platforms ...

AI Security Engineer

Seattle, WA · On-site

$88 - $142/hr

... using Azure Sentinel (SIEM), writing and tuning KQL queries for detection rules, alert triage, and threat hunting.- Maintain and execute incident response playbooks specific to AI platforms ...

New

... Azure Sentinel, and Microsoft Entra/Azure Active Directory, with the ability to leverage these ... Proficiency with automation tools or scripting (e.g., Ansible, Python, KQL, PowerShell) preferred.

Senior Microsoft Security Engineer

Murphy, TX · Remote

$109K - $150K/yr

Map existing Sentinel analytics rules, KQL logic, and detection coverage to Defender XDR ... Experience with Azure Logic Apps, Power Automate, or similar automation platforms * Background in ...

Posted today

Senior Microsoft Security Engineer

Murphy, TX · Remote

$109K - $150K/yr

Map existing Sentinel analytics rules, KQL logic, and detection coverage to Defender XDR ... Experience with Azure Logic Apps, Power Automate, or similar automation platforms * Background in ...

Posted today

Security Administrator

Rosemont, IL · On-site

$100K - $125K/yr

... Azure, Microsoft Entra ID, Microsoft 365, and traditional infrastructure. This is not a policy ... Operate, tune, and build detections in Microsoft Sentinel (KQL for analytics rules, hunting queries ...

Microsoft Administrator

Austin, TX · Remote

$60K - $75K/yr

Build, tune, and improve Microsoft Sentinel detections using KQL to reduce noise and improve ... Azure AdministratorAZ-900 - Azure FundamentalsCompTIA Security+CompTIA Network+CompTIA CySA ...

Microsoft Administrator

Austin, TX · On-site

$60K - $75K/yr

Build, tune, and improve Microsoft Sentinel detections using KQL to reduce noise and improve ... Azure Fundamentals CompTIA Security+ CompTIA Network+ CompTIA CySA+ - Cybersecurity Analyst ...

Microsoft security tools such as Defender, Sentinel, or Entra/Azure AD * Basic scripting or automation exposure with PowerShell, Python, KQL, or Ansible Recruitment Transparency Notice Eliassen Group ...

Senior Microsoft Security Engineer

Houston, TX · On-site

$109K - $149K/yr

The ideal candidate will have deep expertise in Microsoft Defender XDR, Microsoft Sentinel ... Build Hunting Queries (KQL) * Develop Automation Rules * Create Logic Apps playbooks * Build ...

Showing results 41-60

Azure Sentinel Kql information

See salary details

$61K

$103K

$129K

How much do azure sentinel kql jobs pay per year?

As of Aug 12, 2026, the average yearly pay for azure sentinel kql in the United States is $103,000.00, according to ZipRecruiter salary data. Most workers in this role earn between $72,500.00 and $122,500.00 per year, depending on experience, location, and employer.

What are some common challenges faced by professionals working with Azure Sentinel KQL, and how can they be addressed?

One common challenge for professionals using Azure Sentinel KQL is efficiently querying and interpreting large volumes of log data while maintaining optimal performance. Navigating the learning curve of KQL syntax and understanding the structure of various data tables can also be complex. To address these challenges, it is helpful to leverage built-in query examples, participate in community forums, and regularly review Microsoft's official documentation for best practices. Collaborating closely with security analysts and IT teams can also streamline the process of creating effective detection rules and incident investigations.

What are the key skills and qualifications needed to thrive as an Azure Sentinel KQL specialist?

To excel as an Azure Sentinel KQL Specialist, you need expertise in security information and event management (SIEM), proficiency in Kusto Query Language (KQL), and a strong understanding of cybersecurity concepts, often supported by certifications like Microsoft Certified: Security Operations Analyst Associate. Familiarity with Azure Sentinel, log analytics workspaces, threat intelligence tools, and incident response platforms is essential. Analytical thinking, attention to detail, and effective communication skills help specialists investigate incidents and convey findings clearly. These skills are vital for efficiently detecting, analyzing, and mitigating security threats in cloud environments.

What is the difference between Azure Sentinel Kql and Security Analyst?

AspectAzure Sentinel KqlSecurity Analyst
Primary RoleWriting queries to analyze security dataMonitoring, investigating, and responding to security incidents
Required SkillsProficiency in Kusto Query Language (KQL), data analysisSecurity best practices, incident response, analytical skills
Work EnvironmentSecurity platforms, cloud environments, data analysis toolsSecurity operations centers, incident response teams
CertificationsAzure certifications, security fundamentalsCompTIA Security+, CISSP, CEH

Azure Sentinel Kql specialists focus on creating and optimizing queries within Azure Sentinel to detect threats, while Security Analysts handle broader security monitoring and incident response. Both roles require security knowledge, but KQL experts are more technical in data analysis, whereas Security Analysts have a wider security scope.

What is Azure Sentinel KQL?

Azure Sentinel KQL refers to the use of Kusto Query Language (KQL) within Microsoft Azure Sentinel, a cloud-native security information and event management (SIEM) solution. KQL is a powerful query language used to search, analyze, and visualize large volumes of data stored in Azure Log Analytics. Security analysts and administrators use KQL in Sentinel to create custom detections, investigate incidents, and build dashboards. Learning KQL is essential for leveraging the full capabilities of Azure Sentinel in threat detection and response.
More about Azure Sentinel Kql jobs
What cities are hiring for Azure Sentinel Kql jobs? Cities with the most Azure Sentinel Kql job openings:
What states have the most Azure Sentinel Kql jobs? States with the most job openings for Azure Sentinel Kql jobs include:
Infographic showing various Azure Sentinel Kql job openings in the United States as of August 2026, with employment types broken down into 87% Full Time, 1% Part Time, and 12% Contract. Highlights an 75% Physical, 9% Hybrid, and 16% Remote job distribution, with an average salary of $103,000 per year, or $49.5 per hour.

Sr Lead Cyber Security Engineering

Northern Trust

Chicago, IL • On-site

$114K - $194K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 22 days ago


Northern Trust rating

8.2

Company rating: 8.2 out of 10

Based on 27 frontline employees who took The Breakroom Quiz


Job description

About Northern Trust


As a global leader in innovative wealth management, asset servicing, asset management and banking services, Northern Trust (Nasdaq: NTRS) is proud to guide the world's most successful individuals, families, corporations and institutions.


Since 1889, we have aligned our efforts with our three guiding Principles That Endure: Service, Expertise, and Integrity. Together, they reflect the three cornerstones of business conduct which we strive to instill in our employees, whom we call partners, and to provide to our clients and the communities we serve worldwide.


With more than 135 years of financial experience and over 24,000 partners, we serve the world's most sophisticated clients using leading technology and exceptional service.


We are seeking a highly skilled Tech lead with deeper expertise in various security products, authentication, authorization, access management, governance. As a key member of Workforce Authentication and Authorization team you lead a team to play a vital role in ensuring the secure implementation of various solutions (Hybrid and Cloud).

Requirements/Responsibilities-

  • Lead Identity centric Workforce Security solutions team to develop authentication and access management solutions
  • Drive the development of identity solutions, access patterns, modern security protocols, practicing Zero trust, least privileged, defense in depth principles
  • Review and provide feedback on Identity and access management related security solutions proposed by stakeholders and can provide consultation to the partners and IT Management
  • In-depth knowledge and experience on Entra ID, EPM, Sentinel, Azure, AWS Security
  • Knowledge on Okta, PingFederate, Entitlement management solutions
  • Strong knowledge on Identities management on Azure AD with OAuth, OIDC, SAML, SSO, MFA, Conditional access policies, MFA, Kerberos, LDAP, Identity Federations etc.
  • Experience in providing security solutions for Java based Micro services, React based frontends and Android/iOS based mobile applications on the Azure
  • Hands-of experience in JWT, session handling, Code signing, Certificate authentication, TLS/SSL, API Security, Application registration, application integration scenarios etc.
  • Awareness of API Management, Firewalls, DLP, VPNs, DNS, Azure Defender, MCAS, Sentinel, WAFs, Application Gateways, NSGs, App Proxy, Radius clusters, CDN etc.
  • Good understanding of Cloud Infrastructure Entitlement Management solution (CIEM) to ensure smooth remediation of toxic combinations, high risk entitlements etc.
  • Understanding and application of threat modeling concepts and methodologies
  • Understanding of Applications security, OWASP standards, security best practices, browser compatibilities/storages/cookies
  • Acts as Workforce cybersecurity expert to in solutions spanning end user computing, proxy solutions, MFA, SSO, conditional accesses, Passwordless, Yubikey, bio-metric solutions, identity and governance scenarios, Secrets Management, automation, role based access control, Privileged identity management, Just in time accesses etc.
  • Participates in solutions to support- token handling, OIDC/ OAuth flows, authorization patterns, identity federation, cloud architectures, cryptograpgy, cloud native services, cloud security etc.
  • Deeper understanding on Cloud Security areas such as Policies, RBAC, activities, identities, privileged access management etc
  • Ability to support operations in troubleshooting complex identity scenarios with hands-on experience on Sentinel/KQL/Audit logs etc.
  • Good understanding of concepts related to docker Security, container orchestartions/Kubernetes
  • Good understanding of AI concepts, Patterns and impact on identity and access management domain

Qualifications

  • Bachelor's degree in computer science or a related discipline and experience in information security, or an equivalent combination of education and work experience.
  • Deep knowledge of application or infrastructure systems architecture, usually having experience with multiple system technologies.
  • Excellent consultative and communication skills, and the ability to work effectively with client, partner, and IT management and staff.
  • Ten years of experience in the Information Security role. Five years of experience as an Tech lead
  • CISSP, CSSP, or Cloud security certification preferred
  • Strong collaboration skills and a analytical ability
  • Certifications on Azure, AWS security will be preferred

Salary Range:

$114,500 - 194,700 USD

Salary range is a good faith estimate of base pay. Northern Trust provides a comprehensive benefits package including retirement benefits (401k and pension), health and welfare benefits (medical, dental, vision, spending accounts and disability), paid time off, parental and caregiver leave, life & accident insurance, and other voluntary and well-being benefits. Northern Trust also provides a discretionary bonus program that may include an equity component.


Work Authorization


Applicants must be authorized to work in the U.S. without the need for employment-based visa sponsorship now or in the future. Northern Trust will not sponsor applicants for U.S. work visa status for this opportunity (no sponsorship is available for H-1B, L-1, TN, O-1, E-3, H-1B1, F-1, J-1, OPT, CPT or any other employment-based visa).


Working with Us


As a Northern Trust partner, you will be part of a flexible and collaborative work culture, which has a strong history of financial strength and stability. Movement within the organization is encouraged, senior leaders are accessible, and you can take pride in working for a company committed to an inclusive workplace and assisting the communities we serve.


Philanthropy is deeply rooted in Northern Trust's history and is an essential element of our culture. Employees around the world give their time and talent to work for the greater good of their communities.


Reasonable Accommodation


Northern Trust is committed to working with and providing adjustments to individuals with health conditions and disabilities. If you need a reasonable accommodation for any part of the employment process, please email our HR Service Center at MyHRHelp@ntrs.com, or alternatively you can discuss your individual requirements with the recruiter you are working with.



What Northern Trust employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom