1

Kql Jobs in Florida (NOW HIRING)

Use Guardz AI agents, Google BigQuery, and query languages such as SQL and KQL to triage, hunt across high-volume logs, and confirm incident scope at machine speed. * Partner with MSPs on major ...

New

Sr. Net developer

Tampa, FL · On-site

$52 - $66.25/hr

Strong troubleshooting skills to identify problems on Azure deployed environment by writing queries in Kusto Query Language (KQL) logs and analyzing logs from azure portal in application insights

Senior Security Engineer

Orlando, FL · On-site

$106K - $146K/yr

Engineer, tune, and operate detections and response workflows across Microsoft Defender XDR and Microsoft Sentinel, including authoring and optimizing KQL queries, analytics rules, workbooks, and ...

Use Guardz AI agents, Google BigQuery, and query languages such as SQL and KQL to triage, hunt across high-volume logs, and confirm incident scope at machine speed. * Partner with MSPs on major ...

New

Senior Insider Threat Engineer

Miami, FL · On-site +1

$109K - $150K/yr

Automation & Tooling - Develop scripts and queries (KQL, PowerShell, Graph API) to automate policy deployment, reporting, and operational health checks across Purview workloads. Metrics & Reporting ...

New

Senior Insider Threat Engineer

Tampa, FL · On-site +1

$108K - $148K/yr

Automation & Tooling - Develop scripts and queries (KQL, PowerShell, Graph API) to automate policy deployment, reporting, and operational health checks across Purview workloads. Metrics & Reporting ...

New

Senior Insider Threat Engineer

Miami, FL · On-site +1

$109K - $150K/yr

Automation & Tooling - Develop scripts and queries (KQL, PowerShell, Graph API) to automate policy deployment, reporting, and operational health checks across Purview workloads. Metrics & Reporting ...

New

Senior Insider Threat Engineer

Tampa, FL · On-site +1

$108K - $148K/yr

Automation & Tooling - Develop scripts and queries (KQL, PowerShell, Graph API) to automate policy deployment, reporting, and operational health checks across Purview workloads. Metrics & Reporting ...

New

Senior Insider Threat Engineer

Miami, FL · On-site +1

$109K - $150K/yr

Automation & Tooling - Develop scripts and queries (KQL, PowerShell, Graph API) to automate policy deployment, reporting, and operational health checks across Purview workloads. Metrics & Reporting ...

New

Senior Insider Threat Engineer

Tampa, FL · On-site +1

$108K - $148K/yr

Automation & Tooling - Develop scripts and queries (KQL, PowerShell, Graph API) to automate policy deployment, reporting, and operational health checks across Purview workloads. Metrics & Reporting ...

New

Senior Security Engineer

Orlando, FL · On-site

$106K - $146K/yr

Engineer, tune, and operate detections and response workflows across Microsoft Defender XDR and Microsoft Sentinel, including authoring and optimizing KQL queries, analytics rules, workbooks, and ...

Engagement Lead - Azure

Tampa, FL · On-site

$60 - $78.25/hr

Hands\-on experience with automation and scripting, including PowerShell, KQL, ARM\/Bicep, Terraform, and Microsoft Graph API. \n * Solid understanding of cloud computing concepts, including multi ...

... languages (e.g., KQL, YARA‑L, Python) • Comfort working across endpoint, network, identity, and SIEM data • Strong analytical and investigative skills • Effective communication and ...

Technical Expertise Strong knowledge of MITRE ATT&CK and adversary tradecraft Experience analyzing threats, exploits, and attacker behavior Proficiency with query and scripting languages (e.g., KQL ...

Cloud FinOps Architect Lead

Ponte Vedra, FL · On-site

$59.25 - $75.50/hr

Deep understanding of EA/MCA agreements, Azure Resource Graph (Kusto/KQL), and retail vs. negotiated rates. • Data Platform Experience: Hands-on experience optimizing Azure Databricks, ADLS, and ...

next page

Showing results 1-20

Kql information

How does a KQL (Kusto Query Language) specialist typically collaborate with security and operations teams in an organization?

A KQL specialist often works closely with security analysts, IT operations, and data engineering teams to develop queries that extract actionable insights from large datasets, such as those in Azure Monitor or Microsoft Sentinel. They help translate business or security requirements into effective queries, visualize data trends, and automate alerting mechanisms. Regular collaboration is essential for troubleshooting issues, optimizing query performance, and ensuring that dashboards and reports accurately reflect organizational needs. This teamwork enables rapid detection and response to incidents, as well as continuous improvement of monitoring solutions.

What is a KQL search?

A KQL (Kusto Query Language) search is a method used by data analysts and security professionals to query large datasets within Microsoft Azure Data Explorer or Azure Sentinel. It involves writing structured queries to filter, analyze, and visualize data efficiently, often requiring familiarity with syntax and operators specific to KQL.

What is the difference between Kql vs Log Analyst?

AspectKqlLog Analyst
Required CredentialsKnowledge of Kusto Query Language, certifications in data analysis or cloud platformsExperience with log analysis, certifications in cybersecurity or IT support
Work EnvironmentPrimarily cloud-based, data analytics platforms, security monitoringIT departments, cybersecurity teams, network operations centers
Employer & Industry UsageTech companies, cloud service providers, security firmsIT firms, cybersecurity agencies, enterprise IT departments
Search & Comparison IntentUnderstanding Kql for data querying and analysisComparing roles in log analysis and security monitoring

While both Kql and Log Analyst roles involve working with data and logs, Kql focuses on writing queries using the Kusto Query Language for data analysis in cloud environments. Log Analysts interpret and manage log data for security and troubleshooting. The roles often overlap but differ mainly in technical focus and tools used.

What are the key skills and qualifications needed to thrive as a KQL (Kusto Query Language) specialist?

To thrive as a KQL Specialist, you need strong expertise in data analysis, proficiency with Kusto Query Language, and experience with data visualization and log analytics platforms, typically supported by a degree in computer science or related fields. Familiarity with Microsoft Azure Monitor, Azure Data Explorer, and related certification such as Microsoft Certified: Azure Data Fundamentals is common. Analytical thinking, problem-solving, and effective communication are crucial soft skills for interpreting data insights and collaborating with cross-functional teams. These skills are essential for extracting actionable intelligence from large datasets and supporting informed business decisions.

What is a KQL (Kusto Query Language) developer?

KQL (Kusto Query Language) developers are professionals who specialize in writing and optimizing queries using KQL, primarily for Microsoft Azure Data Explorer, Log Analytics, and other services that use Kusto databases. Their responsibilities include designing data queries, building dashboards, analyzing large datasets, and troubleshooting issues within the data pipelines. KQL developers are skilled in constructing efficient queries to retrieve, manipulate, and visualize data, helping organizations gain insights from their logs and telemetry. They often work closely with data engineers, analysts, and IT teams to ensure accurate and actionable data reporting.

What jobs use KQL?

Jobs that use KQL (Kusto Query Language) are typically found in roles involving data analysis, cybersecurity, and IT operations, such as security analysts, data analysts, and cloud engineers. These professionals use KQL to query large datasets in platforms like Azure Data Explorer and Microsoft Sentinel for monitoring, troubleshooting, and security investigations.
Infographic showing various Kql job openings in Florida as of August 2026, with employment types broken down into 20% Internship, 60% Full Time, and 20% Contract. Highlights an 100% In-person job distribution.

MDR Manager

Guardz

Miami, FL • On-site

Other

Posted 3 days ago

New


Job description

We are looking for an experienced MDR Manager to lead our Security Operations team. The ideal candidate combines strong technical expertise with operational leadership and enjoys developing analysts, improving processes, and managing complex security incidents across multi-tenant MSP environments.

As a hands-on leader, you will oversee day-to-day MDR operations, including coverage, SLAs, quality, escalation tiers, and analyst development. You will also serve as the final escalation point for Tier 3 threats and lead the team through the most complex investigations.

Responsibilities:

  • Own 24/7 shift coverage, tiering, and escalation paths so every alert reaches the right analyst and there are no gaps in monitoring or escalation. Participate in an on-call rotation with the team.
  • Own response SLAs (time-to-triage, time-to-notify, MTTR) and report SOC KPIs (MTTD, MTTR, detection efficacy, false-positive rate, case aging, customer satisfaction) to leadership.
  • Run QA on closed alerts and incidents, drive down false positives, and maintain the team's runbooks, playbooks, and SOC standards.
  • Lead, coach, and mentor MDR Analysts: regular 1:1s, performance feedback, onboarding, and the T1-to-T3 training path. Run tabletop exercises and post-incident reviews.
  • Act as technical lead and final escalation point for T3 incidents (advanced malware, identity threats like MFA fatigue and token theft, active breaches), leading the full lifecycle with defensible documentation.
  • Correlate alerts across EDR (SentinelOne, Defender for Endpoint), ITDR (M365, Google Workspace), and email security, and run proactive threat hunts aligned to MITRE ATT&CK.
  • Use Guardz AI agents, Google BigQuery, and query languages such as SQL and KQL to triage, hunt across high-volume logs, and confirm incident scope at machine speed.
  • Partner with MSPs on major incidents and posture reviews, and feed findings back into detection with product, threat research, and engineering.

Requirements:

  • 5+ years in SOC, MDR, or Incident Response handling complex attacks, including 2+ years as a Team Lead, Shift Lead, or senior.
  • Hands-on expertise with EDR (SentinelOne, CrowdStrike, Defender for Endpoint) and ITDR (identity threat management across M365 and Google Workspace).
  • Hands-on experience with Google BigQuery, Snowflake, Splunk, Elastic, or equivalent, and fluency in a query language such as SQL, KQL, or SPL.
  • Experience with MITRE ATT&CK-aligned detection, proactive threat hunting, and AI-driven triage engines, automated playbooks, or agentic SecOps platforms.
  • Excellent communication skills, able to make high-risk technical findings clear to both technical and non-technical audiences.
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or equivalent hands-on experience.
  • Preferred: CompTIA Security+, CompTIA CySA+, Microsoft SC-200, GIAC GCIH / GCIA / GCFA, or CISSP (or equivalent DoD 8570 / 8140 IAT Level II).