← Back to results

kql jobs in San Diego

$97,600 – $200,600 · Posted 3 days ago

Senior Consultant supporting Deloitte's SOC with hands-on Microsoft Sentinel administration, KQL query development, and threat hunting. The role requires 8+ years of technology experience with at least 3 years in SIEM administration, specifically building and tuning analytics rules, developing detection logic, and managing the SIEM data model.… Responsibilities include operational support for Azure and Microsoft Defender portals, incident response guidance, and potential SOAR/automation work with Azure Logic Apps.

San DiegoLast seen 3 days ago
Posted 6 days ago

Lead high-severity incident investigations, mentor L1/L2 analysts, and drive detection engineering at a cybersecurity services firm. Responsibilities include threat hunting, malware analysis, digital/network forensics, SIEM/EDR tuning (KQL, SPL, Sigma, YARA), playbook development, and automation scripting in Python/PowerShell/Bash.… This is a 5+ year senior incident responder role requiring deep hands-on expertise across the full incident response lifecycle, MITRE ATT&CK, and client-facing technical briefings.

San DiegoLast seen 4 days ago
$69,300 – $158,000 · Posted 12 days ago

Lead the design and implementation of advanced security capabilities within Microsoft Azure Government, with responsibility for Azure security architecture, Microsoft Sentinel, Defender, Azure Policy, identity, logging, DevSecOps, and Infrastructure as Code. Guide a small engineering team through technical workstreams that strengthen cloud security, modernize cyber operations, improve security telemetry, and advance continuous security assurance aligned with federal requirements.… Move fluidly between architecture and hands-on engineering to drive work from concept through operational adoption, including identifying configuration drift, automating response, and creating measurable evidence of security control effectiveness. Modernize security data and logging architectures to optimize telemetry collection and maintain visibility against sophisticated threats.

San DiegoLast seen 10 days ago
$98,100 – $171,398 · Posted 17 days ago

This role designs, implements, and optimizes enterprise security systems including firewalls, VPNs, and segmentation controls while developing automation scripts to streamline deployments and enhance threat detection. The architect will leverage network observability and security telemetry to validate policies, identify vulnerabilities, manage patch compliance, and produce metrics for operational visibility.… Responsibilities include mentoring security teams, advising on security best practices aligned with business needs, and collaborating on process improvements and incident response workflows. Required: 5+ years progressive cybersecurity experience (3+ with master's degree); preferred: hands-on NGFW expertise, intermediate certifications (GSEC, CEH, CySA+), and scripting proficiency in Python, PowerShell, Bash, or Java.

San DiegoLast seen 15 days ago
$86,900 – $198,000 · Posted 1 month ago

Lead the design and implementation of advanced security capabilities within Microsoft Azure Government, driving technical workstreams across Azure security architecture, Microsoft Sentinel, Defender, Azure Policy, identity, logging, and Infrastructure as Code. You will architect cloud security solutions, modernize security data and logging architectures, automate configuration-drift detection and response, and guide a small engineering team from concept through operational adoption.… The role requires 5+ years of Azure security engineering experience, expertise with Azure Government, Sentinel, Defender, Azure Monitor, Terraform, and cloud identity platforms, plus the ability to move between architecture and hands-on engineering work.

San DiegoLast seen 1 month ago
$86,900 – $198,000 · Posted 1 month ago

Lead the design and implementation of advanced security capabilities within Microsoft Azure Government, driving technical workstreams across cloud security architecture, Microsoft Sentinel, Defender, Azure Policy, identity, logging, DevSecOps, and Infrastructure as Code. Modernize security data and logging architectures to collect appropriate telemetry, identify configuration drift, validate security controls, automate response, and create measurable evidence of security posture.… Guide a small engineering team from concept through operational adoption, balancing architecture-level strategy with hands-on engineering execution. This role requires 5+ years of Azure security experience, hands-on expertise with Sentinel, Defender, and Azure Monitor, and the ability to align solutions with federal security requirements.

San DiegoLast seen 1 month ago
$73,700 – $128,780 · Posted 1 month ago

This role combines incident response, forensic analysis, and security operations responsibilities, requiring hands-on experience with cybersecurity tools, patch management, and security system optimization. The analyst will develop automation scripts (Python, PowerShell, Bash), manage firewalls and VPN systems, leverage network observability and security telemetry for threat detection, and support incident response workflows.… The position demands 2–5 years of progressive cybersecurity experience, intermediate certifications (GSEC, CEH, CySA+), and familiarity with NGFW technologies, cloud platforms (AWS, Azure), and security frameworks.

San DiegoLast seen 1 month ago
$139,530 – $172,360 · Posted 1 month ago

Staff Engineer II leads the enterprise observability platform as technical SME for Elasticsearch, Kibana, Logstash, and supporting infrastructure. Responsibilities include designing and optimizing Elasticsearch index templates, data lifecycle management policies, and shard allocation strategies; engineering Logstash data ingestion pipelines with log parsing and transformation; managing Azure monitoring services including Log Analytics Workspaces and Event Hubs; and developing Ansible automation for deployment and configuration management across Linux/Unix environments.… The role requires 7+ years in IT App Support, IT Development, IT Networking, or similar; a bachelor's degree; proficiency in Elasticsearch, Kibana, Logstash, KQL, Bash, and PowerShell/Azure CLI; and proven leadership experience managing cross-functional teams and multiple projects simultaneously.

San DiegoLast seen 1 month ago