We are seeking a skilled and proactive Azure Data Explorer (ADX) Administrator to join our SIEM Modernization initiative. This role is critical to enhancing our security telemetry infrastructure, enabling real-time threat detection, and improving operational visibility across the enterprise. This consultant will configure, monitor, and maintain Azure Data Explorer clusters and databases. Manage ingestion pipelines for high-volume security telemetry data. Optimize query performance and resource utilization. Collaborate with cybersecurity teams to integrate ADX with SIEM tools (e.g., Azure Sentinel). Develop KQL-based queries and dashboards for threat detection and incident response. Support real-time alerting and correlation logic across multiple data sources. Implement role-based access control (RBAC) and data retention policies. Ensure compliance with internal security standards and regulatory requirements. Monitor for anomalies and unauthorized access to sensitive data.
We are a company committed to creating inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity employer that believes everyone matters. Qualified candidates will receive consideration for employment opportunities without regard to race, religion, sex, age, marital status, national origin, sexual orientation, citizenship status, disability, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to
Human Resources Request Form. The EEOC "Know Your Rights" Poster is available
here.
To learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy:
https://insightglobal.com/workforce-privacy-policy/ .
Proven experience administering Azure Data Explorer (Kusto).
Strong knowledge of KQL, Azure Monitor, and Log Analytics.
Familiarity with SIEM platforms and security telemetry concepts.
Experience with Azure services such as Data Factory, Synapse, and Sentinel.
Understanding of RBAC, conditional access, and data governance.
Excellent troubleshooting, communication, and documentation skills
Benefit packages for this role will start on the 31st day of employment and include medical, dental, and vision insurance, as well as HSA, FSA, and DCFSA account options, and 401k retirement account access with employer matching. Employees in this role are also entitled to paid sick leave and/or other paid time off as provided by applicable law.