1

Kql Jobs in Washington (NOW HIRING)

Use Guardz AI agents, Google BigQuery, and query languages such as SQL and KQL to triage, hunt across high-volume logs, and confirm incident scope at machine speed. * Partner with MSPs on major ...

Demonstrated significant experience with Microsoft Sentinel: alert monitoring, KQL log queries, entity analysis, runbooks, or escalation. * Demonstrated significant experience with Azure skills ...

New

Demonstrated significant experience with Microsoft Sentinel: alert monitoring, KQL log queries, entity analysis, runbooks, or escalation * Demonstrated significant experience with Azure skills ...

New

Showing results 21-40

Kql information

See Washington salary details

$12

$77

$144

How much do kql jobs pay per hour?

As of Sep 8, 2026, the average hourly pay for kql in Washington is $77.17, according to ZipRecruiter salary data. Most workers in this role earn between $51.20 and $98.03 per hour, depending on experience, location, and employer.

What is a KQL (Kusto Query Language) developer?

KQL (Kusto Query Language) developers are professionals who specialize in writing and optimizing queries using KQL, primarily for Microsoft Azure Data Explorer, Log Analytics, and other services that use Kusto databases. Their responsibilities include designing data queries, building dashboards, analyzing large datasets, and troubleshooting issues within the data pipelines. KQL developers are skilled in constructing efficient queries to retrieve, manipulate, and visualize data, helping organizations gain insights from their logs and telemetry. They often work closely with data engineers, analysts, and IT teams to ensure accurate and actionable data reporting.

What are the key skills and qualifications needed to thrive as a KQL (Kusto Query Language) specialist?

To thrive as a KQL Specialist, you need strong expertise in data analysis, proficiency with Kusto Query Language, and experience with data visualization and log analytics platforms, typically supported by a degree in computer science or related fields. Familiarity with Microsoft Azure Monitor, Azure Data Explorer, and related certification such as Microsoft Certified: Azure Data Fundamentals is common. Analytical thinking, problem-solving, and effective communication are crucial soft skills for interpreting data insights and collaborating with cross-functional teams. These skills are essential for extracting actionable intelligence from large datasets and supporting informed business decisions.

How does a KQL (Kusto Query Language) specialist typically collaborate with security and operations teams in an organization?

A KQL specialist often works closely with security analysts, IT operations, and data engineering teams to develop queries that extract actionable insights from large datasets, such as those in Azure Monitor or Microsoft Sentinel. They help translate business or security requirements into effective queries, visualize data trends, and automate alerting mechanisms. Regular collaboration is essential for troubleshooting issues, optimizing query performance, and ensuring that dashboards and reports accurately reflect organizational needs. This teamwork enables rapid detection and response to incidents, as well as continuous improvement of monitoring solutions.

What is the difference between Kql vs Log Analyst?

AspectKqlLog Analyst
Required CredentialsKnowledge of Kusto Query Language, certifications in data analysis or cloud platformsExperience with log analysis, certifications in cybersecurity or IT support
Work EnvironmentPrimarily cloud-based, data analytics platforms, security monitoringIT departments, cybersecurity teams, network operations centers
Employer & Industry UsageTech companies, cloud service providers, security firmsIT firms, cybersecurity agencies, enterprise IT departments
Search & Comparison IntentUnderstanding Kql for data querying and analysisComparing roles in log analysis and security monitoring

While both Kql and Log Analyst roles involve working with data and logs, Kql focuses on writing queries using the Kusto Query Language for data analysis in cloud environments. Log Analysts interpret and manage log data for security and troubleshooting. The roles often overlap but differ mainly in technical focus and tools used.

What jobs use KQL?

Jobs that use KQL (Kusto Query Language) are typically in data analysis, cybersecurity, and IT operations roles, such as security analysts, data analysts, and cloud engineers. These professionals use KQL to query large datasets in platforms like Azure Data Explorer and Microsoft Sentinel for monitoring, security investigations, and data insights.

What cities in Washington are hiring for Kql jobs?

Cities in Washington with the most Kql job openings:

Infographic showing various Kql job openings in Washington as of August 2026, with employment types broken down into 16% Internship, 47% Full Time, and 37% Contract. Highlights an 80% In-person, and 20% Remote job distribution, with an average salary of $160,521 per year, or $77.2 per hour.

4272 Senior Security Engineer with Security Clearance

Procession Systems

Quantico, VA • On-site

$123K - $169K/yr

Other

Re-posted 15 days ago


Job description

OVERVIEW: We are seeking a highly skilled Senior Security Engineer to provide expertise, guidance, recommendations and document security configurations for the implementation of security tools and processes for government networks. The Senior Security Engineer shall include the installation, analysis, and troubleshooting of data/security networks and devices to include network and software system. GENERAL DUTIES: * Develop technical solutions and new security tools to help mitigate security vulnerability and automate repeatable tasks;
* Assist security personnel with responding to incidents across a wide array of technologies, mitigate and contain impacts, coordinate remediation efforts, and summarize recommendations for improvements;
* Provide up-to-date reports on security incidents and task process; and
* Maintain documentation to support security strategies by outlining the requirements and benefits of specific security tools and/or solutions.
REQUIRED QUALIFICATIONS: * At least six (6) years of experience as Security Analyst in a corporation, government, or service firm.
* Experience using and administering SIEM and analytics solutions (Splunk, Elastic Stack (Elasticsearch, Logstash, Kibana - ELK), or similar) required.
* Experience conducting security assessments, penetration testing and/or ethical hacking, and identifying and mitigating vulnerabilities required.
* Ability to engineer and deploy critical security analytic services including, but not limited to, IPS/IDS, EDR, and SIEM solutions to secure the enterprise.
* Industry security certification such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CSIM), Security+, or similar certification is required.
* Bachelor of Science Degree in Computer Science, Computer Engineering, Cybersecurity or related field of study; or in lieu of education, five additional years of relevant experience.
DESIRED QUALIFICATIONS: * Architect and operate a hybrid SIEM stack spanning Microsoft Sentinel and Splunk Enterprise across on-prem, Azure, AWS; design ingestion pipelines (DCR/AMA, Splunk UF/HF/HEC), normalization with ASIM/CIM, and cross-workspace/cross-tenant event sharing.
* Lead security architecture reviews and reference designs aligned to Zero Trust, NIST 800-53/207, CNSSI 1253; deliver threat models, control mappings, and security data flow diagrams for collection networks.
* Build and maintain detections-as-code: author and version KQL/SPL analytics, watchlists, and entity behavior rules with MITRE ATT&CK coverage.
* Administer a proactive threat-hunting program using KQL/SPL, Jupyter notebooks (MSTICPy), Sigma conversion, and purple-team ATT&CK emulations; convert hunt findings into resilient analytics and anomaly baselines.
* Optimize telemetry governance and cost: table/namespace policies, retention tiers/archival, Splunk license & index strategy, Sentinel ingestion caps and data filters, plus egress controls for FOUO/SCI data.
* Establish incident response operations and SLOs: unify case management (Sentinel Incidents, Splunk ES Notables), evidence handling, post-incident reviews, and executive dashboards/metrics for readiness and dwell time.
* Provide tiered platform support and enablement: backlog grooming, rule/playbook QA, change control, analyst/admin training, and ATO/RMF continuous monitoring package updates as required.
CLEARANCE: * Top Secret clearance and the ability to obtain a CI clearance with a polygraph.

Procession Systems logo

About Procession Systems

Sourced by ZipRecruiter

Procession Systems, based in Reston, Virginia, United States, is an industry leader operating in the Information Technology Services sector. Established to address complex business and technology challenges, the company delivers innovative tech solutions for government entities, primarily focusing on systems integration and software development. Procession Systems takes pride in their commitment to quality, responsiveness, and results, geared towards improving public sector services and saving taxpayer dollars.

Industry

Recruiting and staffing services

Company size

11 - 50 Employees

Headquarters location

Reston, VA, US

Year founded

2016

Social media