1

Kql Jobs in Washington (NOW HIRING)

Scripting and query language knowledge (Python, Splunk Query Language, KQL) * Security Monitoring and Intrusion Detection (e.g. Log correlation and analysis, Incident Response, Forensics)

Microsoft Cloud Security Engineer

Washington, DC · On-site

$63.25 - $84.50/hr

Experience with Microsoft Defender for Cloud, Microsoft Sentinel, and KQL for custom analytics rules and threat hunting is required. You should be familiar with Microsoft Purview and data governance ...

Senior Microsoft Cloud Security Engineer

Arlington, VA · On-site

$131K - $180K/yr

... KQL) queries for Azure Sentinel, Defender, and log analytics. - Review and remediate security controls through vulnerability assessments, penetration tests, and red/blue team engagements. - Guide ...

New

Microsoft Cloud Security Engineer

Washington, DC · On-site

$63.25 - $84.50/hr

Experience with Microsoft Defender for Cloud, Microsoft Sentinel, and KQL for custom analytics rules and threat hunting is required. You should be familiar with Microsoft Purview and data governance ...

Showing results 41-60

Kql information

See Washington salary details

$12

$77

$144

How much do kql jobs pay per hour?

As of Sep 5, 2026, the average hourly pay for kql in Washington is $77.17, according to ZipRecruiter salary data. Most workers in this role earn between $51.20 and $98.03 per hour, depending on experience, location, and employer.

What is a KQL (Kusto Query Language) developer?

KQL (Kusto Query Language) developers are professionals who specialize in writing and optimizing queries using KQL, primarily for Microsoft Azure Data Explorer, Log Analytics, and other services that use Kusto databases. Their responsibilities include designing data queries, building dashboards, analyzing large datasets, and troubleshooting issues within the data pipelines. KQL developers are skilled in constructing efficient queries to retrieve, manipulate, and visualize data, helping organizations gain insights from their logs and telemetry. They often work closely with data engineers, analysts, and IT teams to ensure accurate and actionable data reporting.

What are the key skills and qualifications needed to thrive as a KQL (Kusto Query Language) specialist?

To thrive as a KQL Specialist, you need strong expertise in data analysis, proficiency with Kusto Query Language, and experience with data visualization and log analytics platforms, typically supported by a degree in computer science or related fields. Familiarity with Microsoft Azure Monitor, Azure Data Explorer, and related certification such as Microsoft Certified: Azure Data Fundamentals is common. Analytical thinking, problem-solving, and effective communication are crucial soft skills for interpreting data insights and collaborating with cross-functional teams. These skills are essential for extracting actionable intelligence from large datasets and supporting informed business decisions.

How does a KQL (Kusto Query Language) specialist typically collaborate with security and operations teams in an organization?

A KQL specialist often works closely with security analysts, IT operations, and data engineering teams to develop queries that extract actionable insights from large datasets, such as those in Azure Monitor or Microsoft Sentinel. They help translate business or security requirements into effective queries, visualize data trends, and automate alerting mechanisms. Regular collaboration is essential for troubleshooting issues, optimizing query performance, and ensuring that dashboards and reports accurately reflect organizational needs. This teamwork enables rapid detection and response to incidents, as well as continuous improvement of monitoring solutions.

What is the difference between Kql vs Log Analyst?

AspectKqlLog Analyst
Required CredentialsKnowledge of Kusto Query Language, certifications in data analysis or cloud platformsExperience with log analysis, certifications in cybersecurity or IT support
Work EnvironmentPrimarily cloud-based, data analytics platforms, security monitoringIT departments, cybersecurity teams, network operations centers
Employer & Industry UsageTech companies, cloud service providers, security firmsIT firms, cybersecurity agencies, enterprise IT departments
Search & Comparison IntentUnderstanding Kql for data querying and analysisComparing roles in log analysis and security monitoring

While both Kql and Log Analyst roles involve working with data and logs, Kql focuses on writing queries using the Kusto Query Language for data analysis in cloud environments. Log Analysts interpret and manage log data for security and troubleshooting. The roles often overlap but differ mainly in technical focus and tools used.

What jobs use KQL?

Jobs that use KQL (Kusto Query Language) are typically in data analysis, cybersecurity, and IT operations roles, such as security analysts, data analysts, and cloud engineers. These professionals use KQL to query large datasets in platforms like Azure Data Explorer and Microsoft Sentinel for monitoring, security investigations, and data insights.

What cities in Washington are hiring for Kql jobs?

Cities in Washington with the most Kql job openings:

Infographic showing various Kql job openings in Washington as of August 2026, with employment types broken down into 16% Internship, 47% Full Time, and 37% Contract. Highlights an 80% In-person, and 20% Remote job distribution, with an average salary of $160,521 per year, or $77.2 per hour.

Endpoint Security Architect

Shield Consulting Solutions

Annapolis Junction, MD

$240K - $250K/yr

Full-time

Medical, Retirement, PTO

Re-posted 7 days ago


Job description

**Active TS/SCI w/Polygraph REQUIRED** Please do not apply if you do not currently possess this level of clearance. 
----------
Telework: None
Basic Requirements:
  • 20 years’ experience as a system engineer
  • Bachelor’s degree in a technical discipline
    • 5 additional years of experience as a system engineer may be substituted for a degree

Job Description:
  • Serves as a principal technical leader and subject matter expert within the National Security Agency’s Enterprise Endpoint Detection and Response (EDR) Program.
  • Operating in a highly classified, multi-domain infrastructure, the successful candidate will drive the strategic architectural design, end-to-end integration, deployment, and optimization of premier endpoint security platforms, specifically Microsoft Defender for Endpoint (MDE) and Trellix HX.
  • This critical role bridges high-level systems architecture with operational defense capabilities, ensuring total endpoint visibility, robust threat containment, and resilient configuration management across all enterprise and mission-critical assets to defend national security infrastructure against sophisticated cyber threats.

Essential Duties and Responsibilities:
  • Responsible for leading the lifecycle engineering and scale-out architecture of MDE and Trellix HX across hybrid environments, including on-premises, cloud, and virtual desktop infrastructures (VDI).
    • This includes authoring complex system engineering and implementation plans, tuning agent configurations and exclusion policies to eliminate mission friction, and monitoring overall endpoint health at scale.
  • Collaborate closely with threat hunting and intelligence analysts to translate actionable threat intelligence into custom technical indicators of compromise (IOCs), utilizing Kusto Query Language (KQL) and YARA rules.
  • Act as a primary technical advisor to Government stakeholders on system risks and engineering considerations, provide advanced forensic support to the SOC during critical high-priority incidents, and actively mentor junior and mid-level engineering personnel within the program.

Required Experience:
  • Microsoft Defender for Endpoint (MDE) Expertise: Proven engineering experience with MDE architecture, deployment strategies via MECM/SCCM or Intune, policy ring management, and advanced hunting using Kusto Query Language (KQL).
  • Trellix HX Expertise: Demonstrated experience engineering, deploying, and managing Trellix HX (formerly FireEye) controllers and agents within air-gapped or highly restricted networks, including the creation of OpenIOC and YARA rules.
  • Operating System & Forensic Knowledge: In-depth technical understanding of Windows, Linux, and macOS internals, including file systems, registry structures, and process execution mechanics.
  • Professional Standards: Compliance with DoD 8570/8140 IAM Level II or III baseline certifications.

Desired Experience:
  • Vendor Certifications: Microsoft Certified: Security Operations Analyst Associate (SC-200), Azure Security Engineer Associate (AZ-500), or Trellix Certified Engineering credentials.
  • Methodologies & Toolsets: Experience with Model-Based Systems Engineering (MBSE), Cameo, and workflow management within the Atlassian Suite (Jira, Confluence).
  • Technical Frameworks: Familiarity with NSA Technical Manual Standards (e.g., NSA DS-89) and defense-in-depth engineering principles.
  • Core Competencies: Strong record of team collaboration, exceptional transparency in managing high-consequence infrastructure, and an aptitude for developing technical leadership pipelines.

Salary: $240,000 - $250,000 annually
----------
Excellent benefits package including 25 days PTO, 11 paid holidays, 100% employer-paid healthcare for employees and dependents – available day 1, 8% 401(k) employer match – immediate vesting.  
Disclaimer: The salary range provided is an estimate based on current market conditions and may be adjusted based on factors such as experience, skills, and qualifications. The final salary offer will be determined after a thorough review of the candidate's background and alignment with the role. Please note that this range is subject to change and should be considered as a guideline rather than a definitive figure.
Shield Consulting Solutions is an equal opportunity/affirmative action employer.  All qualified applicants will receive consideration for employment without regard to sex, gender identity, sexual orientation, race, color, religion, national origin, disability, protected Veteran status, age, or any other characteristic protected by law.