Develop, optimize, and maintain KQL queries, analytics rules, detection rules, alerts, workbooks, and dashboards. * Develop automated security response workflows using Azure Logic Apps and Microsoft ...
Develop, optimize, and maintain KQL queries, analytics rules, detection rules, alerts, workbooks, and dashboards. * Develop automated security response workflows using Azure Logic Apps and Microsoft ...
Develop, optimize, and maintain KQL queries, analytics rules, detection rules, alerts, workbooks, and dashboards. * Develop automated security response workflows using Azure Logic Apps and Microsoft ...
Develop, optimize, and maintain KQL queries, analytics rules, detection rules, alerts, workbooks, and dashboards. * Develop automated security response workflows using Azure Logic Apps and Microsoft ...
Develop, optimize, and maintain KQL queries, analytics rules, detection rules, alerts, workbooks, and dashboards. * Develop automated security response workflows using Azure Logic Apps and Microsoft ...
Develop, optimize, and maintain KQL queries, analytics rules, detection rules, alerts, workbooks, and dashboards. * Develop automated security response workflows using Azure Logic Apps and Microsoft ...
Develop, optimize, and maintain KQL queries, analytics rules, detection rules, alerts, workbooks, and dashboards. * Develop automated security response workflows using Azure Logic Apps and Microsoft ...
Develop, optimize, and maintain KQL queries, analytics rules, detection rules, alerts, workbooks, and dashboards. * Develop automated security response workflows using Azure Logic Apps and Microsoft ...
Develop, optimize, and maintain KQL queries, analytics rules, detection rules, alerts, workbooks, and dashboards. * Develop automated security response workflows using Azure Logic Apps and Microsoft ...
Develop, optimize, and maintain KQL queries, analytics rules, detection rules, alerts, workbooks, and dashboards. * Develop automated security response workflows using Azure Logic Apps and Microsoft ...
Senior Platform Engineer (Cloud Workloads)
$127K - $172K/yr
Elastic Stack - Elasticsearch, Kibana, Elastic Fleet, KQL, Query DSL * Azure Kubernetes Service (AKS), Azure Container Apps, VMs * Azure Security - Entra ID, Managed Identities (user/system assigned ...
Senior Platform Engineer (Cloud Workloads)
$127K - $172K/yr
Elastic Stack - Elasticsearch, Kibana, Elastic Fleet, KQL, Query DSL * Azure Kubernetes Service (AKS), Azure Container Apps, VMs * Azure Security - Entra ID, Managed Identities (user/system assigned ...
Develop, optimize, and maintain KQL queries, analytics rules, detection rules, alerts, workbooks, and dashboards. * Develop automated security response workflows using Azure Logic Apps and Microsoft ...
Develop, optimize, and maintain KQL queries, analytics rules, detection rules, alerts, workbooks, and dashboards. * Develop automated security response workflows using Azure Logic Apps and Microsoft ...
Develop, optimize, and maintain KQL queries, analytics rules, detection rules, alerts, workbooks, and dashboards. * Develop automated security response workflows using Azure Logic Apps and Microsoft ...
Develop, optimize, and maintain KQL queries, analytics rules, detection rules, alerts, workbooks, and dashboards. * Develop automated security response workflows using Azure Logic Apps and Microsoft ...
Develop, optimize, and maintain KQL queries, analytics rules, detection rules, alerts, workbooks, and dashboards. * Develop automated security response workflows using Azure Logic Apps and Microsoft ...
Develop, optimize, and maintain KQL queries, analytics rules, detection rules, alerts, workbooks, and dashboards. * Develop automated security response workflows using Azure Logic Apps and Microsoft ...
Develop, optimize, and maintain KQL queries, analytics rules, detection rules, alerts, workbooks, and dashboards. * Develop automated security response workflows using Azure Logic Apps and Microsoft ...
Develop, optimize, and maintain KQL queries, analytics rules, detection rules, alerts, workbooks, and dashboards. * Develop automated security response workflows using Azure Logic Apps and Microsoft ...
Develop, optimize, and maintain KQL queries, analytics rules, detection rules, alerts, workbooks, and dashboards. * Develop automated security response workflows using Azure Logic Apps and Microsoft ...
Develop, optimize, and maintain KQL queries, analytics rules, detection rules, alerts, workbooks, and dashboards. * Develop automated security response workflows using Azure Logic Apps and Microsoft ...
... hunting queries (KQL). · Builds and maintains analytics content, data parsers, normalization rules, and entity behavior profiles. · Evaluates behavioral anomalies and collaborates with ...
Quick apply
... hunting queries (KQL). · Builds and maintains analytics content, data parsers, normalization rules, and entity behavior profiles. · Evaluates behavioral anomalies and collaborates with ...
Develop, optimize, and maintain KQL queries, analytics rules, detection rules, alerts, workbooks, and dashboards. * Develop automated security response workflows using Azure Logic Apps and Microsoft ...
Develop, optimize, and maintain KQL queries, analytics rules, detection rules, alerts, workbooks, and dashboards. * Develop automated security response workflows using Azure Logic Apps and Microsoft ...
Develop, optimize, and maintain KQL queries, analytics rules, detection rules, alerts, workbooks, and dashboards. * Develop automated security response workflows using Azure Logic Apps and Microsoft ...
Develop, optimize, and maintain KQL queries, analytics rules, detection rules, alerts, workbooks, and dashboards. * Develop automated security response workflows using Azure Logic Apps and Microsoft ...
The ideal candidate brings strong experience in observability platforms such as Dynatrace and Azure Application Insights, advanced KQL-based diagnostics, and the ability to troubleshoot complex ...
The ideal candidate brings strong experience in observability platforms such as Dynatrace and Azure Application Insights, advanced KQL-based diagnostics, and the ability to troubleshoot complex ...
Microsoft Administrator
Austin, TX · On-site
$60K - $75K/yr
Microsoft Sentinel and KQL queries/detection engineering * PowerShell scripting and automation * SIEM platforms * Security operations or SOC experience Preferred Certifications & Training ...
Microsoft Administrator
Austin, TX · On-site
$60K - $75K/yr
Microsoft Sentinel and KQL queries/detection engineering * PowerShell scripting and automation * SIEM platforms * Security operations or SOC experience Preferred Certifications & Training ...
Microsoft Administrator
Austin, TX · On-site
$60K - $75K/yr
Microsoft Sentinel and KQL queries/detection engineering * PowerShell scripting and automation * SIEM platforms * Security operations or SOC experience Preferred Certifications ...
Microsoft Administrator
Austin, TX · On-site
$60K - $75K/yr
Microsoft Sentinel and KQL queries/detection engineering * PowerShell scripting and automation * SIEM platforms * Security operations or SOC experience Preferred Certifications ...
Technology Lead | Cloud Platform | Azure Development & Solution Architecting
Chicago, IL · On-site
$65.50 - $85.25/hr
Yes Must Have Skills: • CI/CD pipelines, • Automation • IaaC - Terraform • Yaml • Liquibase • Azure Cloud Infrastructure • Grafana • Prometheus • KQL • AppInsights • Monitoring ...
Technology Lead | Cloud Platform | Azure Development & Solution Architecting
Chicago, IL · On-site
$65.50 - $85.25/hr
Yes Must Have Skills: • CI/CD pipelines, • Automation • IaaC - Terraform • Yaml • Liquibase • Azure Cloud Infrastructure • Grafana • Prometheus • KQL • AppInsights • Monitoring ...
Develop, optimize, and maintain KQL queries, analytics rules, detection rules, alerts, workbooks, and dashboards. * Develop automated security response workflows using Azure Logic Apps and Microsoft ...
Develop, optimize, and maintain KQL queries, analytics rules, detection rules, alerts, workbooks, and dashboards. * Develop automated security response workflows using Azure Logic Apps and Microsoft ...
Develop, optimize, and maintain KQL queries, analytics rules, detection rules, alerts, workbooks, and dashboards. * Develop automated security response workflows using Azure Logic Apps and Microsoft ...
Develop, optimize, and maintain KQL queries, analytics rules, detection rules, alerts, workbooks, and dashboards. * Develop automated security response workflows using Azure Logic Apps and Microsoft ...
Kql information
See salary details
$11.30 - $21.85
12% of jobs
$21.85 - $32.41
3% of jobs
$42.70 is the 25th percentile. Wages below this are outliers.
$32.41 - $42.96
11% of jobs
$42.96 - $53.52
11% of jobs
The median wage is $61.43 / hr.
$53.52 - $64.07
19% of jobs
$64.07 - $74.63
18% of jobs
$78.59 is the 75th percentile. Wages above this are outliers.
$74.63 - $85.18
6% of jobs
$85.18 - $95.74
2% of jobs
$95.74 - $106.29
3% of jobs
$106.29 - $116.85
0% of jobs
$116.85 - $127.40
16% of jobs
$11
$68
$127
How much do kql jobs pay per hour?
What is a KQL (Kusto Query Language) developer?
What are the key skills and qualifications needed to thrive as a KQL (Kusto Query Language) specialist?
How does a KQL (Kusto Query Language) specialist typically collaborate with security and operations teams in an organization?
What is the difference between Kql vs Log Analyst?
| Aspect | Kql | Log Analyst |
|---|---|---|
| Required Credentials | Knowledge of Kusto Query Language, certifications in data analysis or cloud platforms | Experience with log analysis, certifications in cybersecurity or IT support |
| Work Environment | Primarily cloud-based, data analytics platforms, security monitoring | IT departments, cybersecurity teams, network operations centers |
| Employer & Industry Usage | Tech companies, cloud service providers, security firms | IT firms, cybersecurity agencies, enterprise IT departments |
| Search & Comparison Intent | Understanding Kql for data querying and analysis | Comparing roles in log analysis and security monitoring |
While both Kql and Log Analyst roles involve working with data and logs, Kql focuses on writing queries using the Kusto Query Language for data analysis in cloud environments. Log Analysts interpret and manage log data for security and troubleshooting. The roles often overlap but differ mainly in technical focus and tools used.
What jobs use KQL?
What are the most commonly searched types of Kql jobs?
The most popular types of Kql jobs are:
What states have the most Kql jobs?
States with the most job openings for Kql jobs include:
What job categories do people searching Kql jobs look for?
The top searched job categories for Kql jobs are:

Full-time
Posted 9 days ago
Job description
We are seeking an experienced Microsoft Sentinel Subject Matter Expert (SME) to design, implement, optimize, and manage Microsoft Sentinel and Azure security solutions. The role will focus on SIEM/SOAR engineering, threat detection, incident response, security automation, cloud security, and compliance across enterprise Azure environments.
Roles and Responsibilities- Design, implement, configure, and manage Microsoft Sentinel SIEM/SOAR solutions.
- Integrate security data sources into Azure Log Analytics, including Syslog, CEF, APIs, and threat intelligence feeds.
- Develop, optimize, and maintain KQL queries, analytics rules, detection rules, alerts, workbooks, and dashboards.
- Develop automated security response workflows using Azure Logic Apps and Microsoft Copilot for Security.
- Perform threat hunting, incident investigation, detection engineering, and response activities in collaboration with SOC teams.
- Implement and manage Azure security controls aligned with Zero Trust principles.
- Configure and secure enterprise Azure environments, including identity, access, monitoring, and security services.
- Assess vulnerabilities, analyze attacker TTPs, and support remediation and security improvement initiatives.
- Integrate and manage Microsoft Defender XDR, including Defender for Endpoint, Office 365, Identity, and Cloud Apps.
- Support cloud security governance, compliance, risk assessments, and audit activities.
- Provide technical guidance on security architecture, SIEM/SOAR strategy, detection engineering, and cloud security initiatives.
- Develop security standards, operational procedures, and best practices for Sentinel and Azure security services.
- Collaborate with Security Operations, Cloud Engineering, Identity, Application Security, and Governance teams.
- Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related field.
- 5+ years of cybersecurity experience, including strong hands-on experience with Microsoft Sentinel engineering and administration.
- Strong expertise in:
- Microsoft Sentinel
- Azure Log Analytics
- Kusto Query Language (KQL)
- Azure Logic Apps
- Microsoft Defender XDR
- Azure Security and Identity Services
- Microsoft Entra ID
- Privileged Identity Management (PIM)
- Conditional Access
- Security monitoring and incident response
- CI/CD security and application security scanning
- Strong understanding of SIEM/SOAR, threat detection, threat hunting, incident response, and security automation.
- Experience implementing security controls in enterprise Azure environments.
- Strong knowledge of Zero Trust architecture and cloud security best practices.
- Experience with Azure Government / Government Cloud environments.
- Experience with FISMA, FedRAMP, and NIST security and compliance frameworks.
- Relevant certifications such as CISSP, CCSP, Microsoft Certified: Azure Security Engineer Associate, or Microsoft Certified: Cybersecurity Architect Expert.
- Experience working with security auditors, compliance teams, and executive stakeholders.