Develop, optimize, and maintain KQL queries, analytics rules, detection rules, alerts, workbooks, and dashboards. * Develop automated security response workflows using Azure Logic Apps and Microsoft ...
Develop, optimize, and maintain KQL queries, analytics rules, detection rules, alerts, workbooks, and dashboards. * Develop automated security response workflows using Azure Logic Apps and Microsoft ...
Develop, optimize, and maintain KQL queries, analytics rules, detection rules, alerts, workbooks, and dashboards. * Develop automated security response workflows using Azure Logic Apps and Microsoft ...
Develop, optimize, and maintain KQL queries, analytics rules, detection rules, alerts, workbooks, and dashboards. * Develop automated security response workflows using Azure Logic Apps and Microsoft ...
Develop, optimize, and maintain KQL queries, analytics rules, detection rules, alerts, workbooks, and dashboards. * Develop automated security response workflows using Azure Logic Apps and Microsoft ...
Develop, optimize, and maintain KQL queries, analytics rules, detection rules, alerts, workbooks, and dashboards. * Develop automated security response workflows using Azure Logic Apps and Microsoft ...
Develop, optimize, and maintain KQL queries, analytics rules, detection rules, alerts, workbooks, and dashboards. * Develop automated security response workflows using Azure Logic Apps and Microsoft ...
Develop, optimize, and maintain KQL queries, analytics rules, detection rules, alerts, workbooks, and dashboards. * Develop automated security response workflows using Azure Logic Apps and Microsoft ...
Develop, optimize, and maintain KQL queries, analytics rules, detection rules, alerts, workbooks, and dashboards. * Develop automated security response workflows using Azure Logic Apps and Microsoft ...
Develop, optimize, and maintain KQL queries, analytics rules, detection rules, alerts, workbooks, and dashboards. * Develop automated security response workflows using Azure Logic Apps and Microsoft ...
Develop, optimize, and maintain KQL queries, analytics rules, detection rules, alerts, workbooks, and dashboards. * Develop automated security response workflows using Azure Logic Apps and Microsoft ...
Develop, optimize, and maintain KQL queries, analytics rules, detection rules, alerts, workbooks, and dashboards. * Develop automated security response workflows using Azure Logic Apps and Microsoft ...
Develop, optimize, and maintain KQL queries, analytics rules, detection rules, alerts, workbooks, and dashboards. * Develop automated security response workflows using Azure Logic Apps and Microsoft ...
Develop, optimize, and maintain KQL queries, analytics rules, detection rules, alerts, workbooks, and dashboards. * Develop automated security response workflows using Azure Logic Apps and Microsoft ...
Develop, optimize, and maintain KQL queries, analytics rules, detection rules, alerts, workbooks, and dashboards. * Develop automated security response workflows using Azure Logic Apps and Microsoft ...
Develop, optimize, and maintain KQL queries, analytics rules, detection rules, alerts, workbooks, and dashboards. * Develop automated security response workflows using Azure Logic Apps and Microsoft ...
IT Support Manager
Atlanta, GA · On-site
Leverage Kusto Query Language (KQL) to analyze telemetry, logs, and metrics to diagnose production issues. * Troubleshoot complex integrations across distributed systems, including APIs, event-driven ...
IT Support Manager
Atlanta, GA · On-site
Leverage Kusto Query Language (KQL) to analyze telemetry, logs, and metrics to diagnose production issues. * Troubleshoot complex integrations across distributed systems, including APIs, event-driven ...
Senior Security Engineer
Indianapolis, IN · On-site
$120 - $180/hr
Own detection engineering and IR day to day -- KQL detections in Log Analytics, Azure Monitor dashboards, SIEM forwarding via Event Hub, and incident.io alerting and runbooks. The Security Lead steps ...
Senior Security Engineer
Indianapolis, IN · On-site
$120 - $180/hr
Own detection engineering and IR day to day -- KQL detections in Log Analytics, Azure Monitor dashboards, SIEM forwarding via Event Hub, and incident.io alerting and runbooks. The Security Lead steps ...
Use Guardz AI agents, Google BigQuery, and query languages such as SQL and KQL to triage, hunt across high-volume logs, and confirm incident scope at machine speed. * Partner with MSPs on major ...
Use Guardz AI agents, Google BigQuery, and query languages such as SQL and KQL to triage, hunt across high-volume logs, and confirm incident scope at machine speed. * Partner with MSPs on major ...
Build monitoring, logging, and auditing solutions using Azure Monitor, Log Analytics, and KQL * Support code reviews, branching strategies, release management, and engineering standards across ...
Quick apply
Build monitoring, logging, and auditing solutions using Azure Monitor, Log Analytics, and KQL * Support code reviews, branching strategies, release management, and engineering standards across ...
Azure Operations Engineer
Charlotte, NC · On-site
Monitor alerts across critical services using Azure Monitor, Log Analytics (KQL), Application Insights, Grafana, and Prometheus, and respond or escalate as appropriate. * Track cloud costs, surface ...
Azure Operations Engineer
Charlotte, NC · On-site
Monitor alerts across critical services using Azure Monitor, Log Analytics (KQL), Application Insights, Grafana, and Prometheus, and respond or escalate as appropriate. * Track cloud costs, surface ...
... KQL (Kusto Query Language) queries to create reports, dashboards, and alerts that enhance visibility into security posture • Collaborate with cross-functional IT, DevSecOps, and mission teams to ...
... KQL (Kusto Query Language) queries to create reports, dashboards, and alerts that enhance visibility into security posture • Collaborate with cross-functional IT, DevSecOps, and mission teams to ...
Detection Engineer
Arlington, VA · On-site
... KQL queries for Sentinel to improve detection fidelity and reduce false positives. • Tune detection sets to raise security-relevant events for triage and response teams. • Maintain version ...
Detection Engineer
Arlington, VA · On-site
... KQL queries for Sentinel to improve detection fidelity and reduce false positives. • Tune detection sets to raise security-relevant events for triage and response teams. • Maintain version ...
Senior Cloud Security Engineer - Cleared (Polygraph)
Reston, VA · On-site
$119K - $163K/yr
... KQL (Kusto Query Language) queries to create reports, dashboards, and alerts that enhance visibility into security posture. • Collaborate with cross-functional IT, DevSecOps, and mission teams to ...
Senior Cloud Security Engineer - Cleared (Polygraph)
Reston, VA · On-site
$119K - $163K/yr
... KQL (Kusto Query Language) queries to create reports, dashboards, and alerts that enhance visibility into security posture. • Collaborate with cross-functional IT, DevSecOps, and mission teams to ...
Detection Engineer
Arlington, VA · On-site
... KQL queries for Sentinel to improve detection fidelity and reduce false positives. • Tune detection sets to raise security-relevant events for triage and response teams. • Maintain version ...
Detection Engineer
Arlington, VA · On-site
... KQL queries for Sentinel to improve detection fidelity and reduce false positives. • Tune detection sets to raise security-relevant events for triage and response teams. • Maintain version ...
ELK / ESS Engineer
Mclean, VA · On-site
Utilize aggregations, date histograms, and filters (KQL) to analyze large datasets and ensure fast dashboard response times. * Alerting & Monitoring: Set up threshold-based alerts (Watcher) and ...
Quick apply
ELK / ESS Engineer
Mclean, VA · On-site
Utilize aggregations, date histograms, and filters (KQL) to analyze large datasets and ensure fast dashboard response times. * Alerting & Monitoring: Set up threshold-based alerts (Watcher) and ...
Engineer, tune, and operate detections and response workflows across Microsoft Defender XDR and Microsoft Sentinel, including authoring and optimizing KQL queries, analytics rules, workbooks, and ...
Engineer, tune, and operate detections and response workflows across Microsoft Defender XDR and Microsoft Sentinel, including authoring and optimizing KQL queries, analytics rules, workbooks, and ...
Senior Cloud Security Engineer - Cleared (Polygraph)
Reston, VA · On-site
$119K - $163K/yr
... KQL (Kusto Query Language) queries to create reports, dashboards, and alerts that enhance visibility into security posture. • Collaborate with cross-functional IT, DevSecOps, and mission teams to ...
Senior Cloud Security Engineer - Cleared (Polygraph)
Reston, VA · On-site
$119K - $163K/yr
... KQL (Kusto Query Language) queries to create reports, dashboards, and alerts that enhance visibility into security posture. • Collaborate with cross-functional IT, DevSecOps, and mission teams to ...
KQL information
See salary details
$11.30 - $21.85
12% of jobs
$21.85 - $32.41
3% of jobs
$42.70 is the 25th percentile. Wages below this are outliers.
$32.41 - $42.96
11% of jobs
$42.96 - $53.52
11% of jobs
The median wage is $61.43 / hr.
$53.52 - $64.07
19% of jobs
$64.07 - $74.63
18% of jobs
$78.59 is the 75th percentile. Wages above this are outliers.
$74.63 - $85.18
6% of jobs
$85.18 - $95.74
2% of jobs
$95.74 - $106.29
3% of jobs
$106.29 - $116.85
0% of jobs
$116.85 - $127.40
16% of jobs
$11
$68
$127
How much do kql jobs pay per hour?
How does a KQL (Kusto Query Language) specialist typically collaborate with security and operations teams in an organization?
What is a KQL search?
What is the difference between Kql vs Log Analyst?
| Aspect | Kql | Log Analyst |
|---|---|---|
| Required Credentials | Knowledge of Kusto Query Language, certifications in data analysis or cloud platforms | Experience with log analysis, certifications in cybersecurity or IT support |
| Work Environment | Primarily cloud-based, data analytics platforms, security monitoring | IT departments, cybersecurity teams, network operations centers |
| Employer & Industry Usage | Tech companies, cloud service providers, security firms | IT firms, cybersecurity agencies, enterprise IT departments |
| Search & Comparison Intent | Understanding Kql for data querying and analysis | Comparing roles in log analysis and security monitoring |
While both Kql and Log Analyst roles involve working with data and logs, Kql focuses on writing queries using the Kusto Query Language for data analysis in cloud environments. Log Analysts interpret and manage log data for security and troubleshooting. The roles often overlap but differ mainly in technical focus and tools used.
What are the key skills and qualifications needed to thrive as a KQL (Kusto Query Language) specialist?
What is a KQL (Kusto Query Language) developer?
What jobs use KQL?
What are the most commonly searched types of Kql jobs?
The most popular types of Kql jobs are:
What states have the most Kql jobs?
States with the most job openings for Kql jobs include:
What job categories do people searching Kql jobs look for?
The top searched job categories for Kql jobs are:

Full-time
Posted 5 days ago
Job description
We are seeking an experienced Microsoft Sentinel Subject Matter Expert (SME) to design, implement, optimize, and manage Microsoft Sentinel and Azure security solutions. The role will focus on SIEM/SOAR engineering, threat detection, incident response, security automation, cloud security, and compliance across enterprise Azure environments.
Roles and Responsibilities- Design, implement, configure, and manage Microsoft Sentinel SIEM/SOAR solutions.
- Integrate security data sources into Azure Log Analytics, including Syslog, CEF, APIs, and threat intelligence feeds.
- Develop, optimize, and maintain KQL queries, analytics rules, detection rules, alerts, workbooks, and dashboards.
- Develop automated security response workflows using Azure Logic Apps and Microsoft Copilot for Security.
- Perform threat hunting, incident investigation, detection engineering, and response activities in collaboration with SOC teams.
- Implement and manage Azure security controls aligned with Zero Trust principles.
- Configure and secure enterprise Azure environments, including identity, access, monitoring, and security services.
- Assess vulnerabilities, analyze attacker TTPs, and support remediation and security improvement initiatives.
- Integrate and manage Microsoft Defender XDR, including Defender for Endpoint, Office 365, Identity, and Cloud Apps.
- Support cloud security governance, compliance, risk assessments, and audit activities.
- Provide technical guidance on security architecture, SIEM/SOAR strategy, detection engineering, and cloud security initiatives.
- Develop security standards, operational procedures, and best practices for Sentinel and Azure security services.
- Collaborate with Security Operations, Cloud Engineering, Identity, Application Security, and Governance teams.
- Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related field.
- 5+ years of cybersecurity experience, including strong hands-on experience with Microsoft Sentinel engineering and administration.
- Strong expertise in:
- Microsoft Sentinel
- Azure Log Analytics
- Kusto Query Language (KQL)
- Azure Logic Apps
- Microsoft Defender XDR
- Azure Security and Identity Services
- Microsoft Entra ID
- Privileged Identity Management (PIM)
- Conditional Access
- Security monitoring and incident response
- CI/CD security and application security scanning
- Strong understanding of SIEM/SOAR, threat detection, threat hunting, incident response, and security automation.
- Experience implementing security controls in enterprise Azure environments.
- Strong knowledge of Zero Trust architecture and cloud security best practices.
- Experience with Azure Government / Government Cloud environments.
- Experience with FISMA, FedRAMP, and NIST security and compliance frameworks.
- Relevant certifications such as CISSP, CCSP, Microsoft Certified: Azure Security Engineer Associate, or Microsoft Certified: Cybersecurity Architect Expert.
- Experience working with security auditors, compliance teams, and executive stakeholders.