Lead Cybersecurity Specialist

<p><span style="font-size: 12pt;"><strong>About Legence</strong></span><br><span style="font-size: 12pt;"><a rel="noopener" href="https://www.wearelegence.com/" target="_blank">Legence</a> (Nasdaq: LGN) is a leading provider of engineering, consulting, installation, and maintenance services for mission-critical systems in buildings. The company specializes in designing, fabricating, and installing complex HVAC, process piping, and other mechanical, electrical, and plumbing (MEP) systems—enhancing energy efficiency, reliability, and sustainability in new and existing facilities. Legence also delivers long-term performance through strategic upgrades and holistic solutions. Serving some of the world’s most technically demanding sectors, Legence counts over 60% of the Nasdaq-100 Index among its clients.</span></p><p><span style="font-size: 12pt;">Location: Remote, United States. Near Legence office preferred. </span></p> <p><span style="font-size: 12pt;">The Lead Cybersecurity Specialist within the Legence IT Security organization will be responsible for helping advance the company’s overall security posture. This role goes beyond operational support to include architecture, risk strategy, and cross-functional leadership. This role will work with other IT pillars and team members to implement, and continuously improve security controls that protect enterprise systems, cloud environments, and data against evolving threats while aligning with business objectives and regulatory requirements.  This role will provide team leadership to junior staff members </span></p> <p><span style="font-size: 12pt;"> <strong>About the Role </strong></span><br><span style="font-size: 12pt;">We are seeking a highly skilled Lead Cybersecurity Specialist to lead a team of cyber analysts tasked with advancing Legence’s security posture and reducing risk.  This role is critical to ensuring the integrity, reliability, and security of our IT systems and processes. The ideal candidate will bring deep cyber experience, the ability to develop team members, the ability to communicate with business and IT partners, and a focus in ITGC audits, tool selection, continuous improvement, and cross-functional project management. </span></p> <p><span style="font-size: 12pt;"><strong>Key Responsibilities </strong></span></p> <ul> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Cloud Security & Architecture</span> <ul> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Ensure the implementation and governance of secure cloud architectures across platforms.</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Continue development, enforcement, and governance of cyber security controls (including identity, access management, and workload protection).</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Partner with engineering teams to embed security into cloud-native development and DevOps processes (DevSecOps).</span></li> </ul> </li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Enterprise Risk Management</span> <ul> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Evolve the organization’s security risk management program.</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Conduct risk assessments, threat modeling, and control evaluations.</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Translate technical risks into business impact and present recommendations to senior leadership.</span></li> </ul> </li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Security Engineering & Automation</span> <ul> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Develop and maintain advanced automation frameworks and scripts to improve detection, response, and compliance capabilities.</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Lead efforts to integrate security tooling (SIEM, EDR, CSPM, etc.) into a cohesive security ecosystem.</span></li> </ul> </li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Threat Detection & Incident Response</span> <ul> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Oversee monitoring and detection strategies across networks, endpoints, and cloud environments.</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Lead incident response efforts, including triage, containment, root cause analysis, and post-incident improvements.</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Drive continuous improvement of detection use cases and response playbooks.</span></li> </ul> </li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Vulnerability Management & Offensive Security</span> <ul> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Lead vulnerability management lifecycle, including scanning, prioritization, and remediation strategies.</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Coordinate perform penetration testing and adversary simulations.</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Provide expert guidance on remediation and risk prioritization.</span></li> </ul> </li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Governance, Compliance & Security Strategy</span> <ul> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Support and help shape governance, risk, and compliance initiatives (e.g., NIST, ISO, SOC 2).</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Lead security assessments, audits, and third-party risk reviews.</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Contribute to long-term cybersecurity strategy, roadmap planning, and security metrics reporting.</span></li> </ul> </li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Leadership & Collaboration</span> <ul> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Act as a technical mentor and escalation point for junior analysts and engineers.</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Oversee the career development of security team members</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Collaborate with IT, engineering, and business stakeholders to align security initiatives with organizational goals.</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Stay ahead of emerging threats, technologies, and industry trends, bringing proactive recommendations to leadership. </span></li> </ul> </li> </ul> <p><span style="font-size: 12pt;"><strong>Qualifications </strong></span></p> <ul> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent experience).</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">5–10+ years of experience in cybersecurity, with demonstrated progression into senior or lead responsibilities.</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Deep expertise in cloud security, network security, and enterprise security architecture.</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Strong experience with security technologies such as SIEM, EDR, IDS/IPS, firewalls, and encryption.</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Proven experience in risk management, incident response, and vulnerability management.</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Proficiency in scripting or programming (e.g., Python, PowerShell, Bash) for automation and security engineering.</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Experience with security frameworks and compliance standards (e.g., NIST, ISO 27001, CIS).</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Strong analytical, problem-solving, and decision-making skills.</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Excellent communication skills, with the ability to influence technical and non-technical stakeholders. </span></li> </ul> <p><span style="font-size: 12pt;"><strong>Preferred Qualifications </strong></span></p> <ul> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Industry certifications such as CISSP, CISM, CCSP, or GIAC.</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Experience leading security initiatives or small teams. </span></li> </ul> <p><span style="font-size: 12pt;">Compensation: $125k-$165k, depending on experience</span></p> <p><span style="font-size: 12pt;">#LI-JS1 #LI-Remote</span></p><p><strong>Benefits Overview</strong><br><strong>401(k) Plan with Company Match:</strong> Currently match contributions dollar-for-dollar up to 4% of eligible pay; immediate vesting. <br><strong>Health & Welfare Benefits:</strong> Employer provided medical, dental, vision, prescription drug, Employee Assistance Program and accident & illness coverage. <br><strong>Life and Disability Insurance</strong>: Employer provided basic life insurance and AD&D valued at 50K coverage amount with the option for voluntary buy up for additional coverage.<br><strong>Time Off:</strong> Flexible non-accrual vacation; company holidays per policy. <em>(For California employees, this is separate from California paid sick leave, if applicable.)</em><br><strong>Expenses</strong>: Business travel and related expenses reimbursed per company policy.</p> <p><strong>Reasonable Accommodations<br></strong>If you need assistance or accommodations during the application or interview process, please contact us at <a rel="noopener" href="mailto:ta@wearelegence.com" target="_blank" title="mailto:ta@wearelegence.com" data-linkindex="0">ta@wearelegence.com</a> or your dedicated recruiter with the <span data-ogsb="" data-ogsc="" data-ogab="" data-ogac="" data-markjs="true">job</span> title and requisition number.</p> <p><strong>Employment Eligibility</strong><br>Candidates must have current work authorization in the U.S.; visa sponsorship is not available for this position.</p> <p><strong>Third-Party Recruiting Disclaimer</strong><br>Legence and its affiliates do not accept unsolicited resumes from agencies; any such submissions without a prior signed agreement authorized by Legence Holdings LLC's CHRO or Director of Talent Acquisition will not incur fees and are considered property of Legence.</p> <p><strong>Pay Disclosure & Considerations</strong><br>Where pay ranges are indicated, please note that a successful candidate’s exact pay will be determined based relevant <span data-ogsb="" data-ogsc="" data-ogab="" data-ogac="" data-markjs="true">job</span>-related factors, including any of the following: candidate’s experience, skills, and qualifications, as well as geographic and market considerations.  We are committed to ensuring fair and competitive compensation for all employees and comply with all applicable salary transparency laws. </p> <p><span style="font-size: 8pt;"><strong>Equal Employment Opportunity Employer<br></strong>Legence and its affiliate companies are proud to be an equal opportunity workplace. We are committed to equal employment opportunity regardless of race, color, religion, sex (including pregnancy, gender identity, and sexual orientation), marital or familial status, national origin, age, disability, genetic information (including family medical history), political affiliation, military service, other non-merit-based factors, and any other characteristic protected under applicable local, state or federal laws and regulations.</span><br><span style="font-size: 8pt;"><a rel="noopener" href="https://nam11.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.eeoc.gov%2Femployers%2Feeo-law-poster&data=05%7C02%7CDivya.Selvaraj%40wearelegence.com%7C492534f848704ab3d99108dd578322ed%7C7bb63ee7a3e14d75b5a56f9549f171a3%7C0%7C0%7C638762942911616035%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=1wutgP6pyxZg1OBPthpEEp1LqTFttzm9dDo6Kpdx88M%3D&reserved=0" target="_blank" title="Original URL: https://www.eeoc.gov/employers/eeo-law-poster. Click or tap if you trust this link." data-linkindex="1" data-auth="NotApplicable">EEO is the Law</a> </span></p>

Back to blog

Common Interview Questions And Answers

1. HOW DO YOU PLAN YOUR DAY?

This is what this question poses: When do you focus and start working seriously? What are the hours you work optimally? Are you a night owl? A morning bird? Remote teams can be made up of people working on different shifts and around the world, so you won't necessarily be stuck in the 9-5 schedule if it's not for you...

2. HOW DO YOU USE THE DIFFERENT COMMUNICATION TOOLS IN DIFFERENT SITUATIONS?

When you're working on a remote team, there's no way to chat in the hallway between meetings or catch up on the latest project during an office carpool. Therefore, virtual communication will be absolutely essential to get your work done...

3. WHAT IS "WORKING REMOTE" REALLY FOR YOU?

Many people want to work remotely because of the flexibility it allows. You can work anywhere and at any time of the day...

4. WHAT DO YOU NEED IN YOUR PHYSICAL WORKSPACE TO SUCCEED IN YOUR WORK?

With this question, companies are looking to see what equipment they may need to provide you with and to verify how aware you are of what remote working could mean for you physically and logistically...

5. HOW DO YOU PROCESS INFORMATION?

Several years ago, I was working in a team to plan a big event. My supervisor made us all work as a team before the big day. One of our activities has been to find out how each of us processes information...

6. HOW DO YOU MANAGE THE CALENDAR AND THE PROGRAM? WHICH APPLICATIONS / SYSTEM DO YOU USE?

Or you may receive even more specific questions, such as: What's on your calendar? Do you plan blocks of time to do certain types of work? Do you have an open calendar that everyone can see?...

7. HOW DO YOU ORGANIZE FILES, LINKS, AND TABS ON YOUR COMPUTER?

Just like your schedule, how you track files and other information is very important. After all, everything is digital!...

8. HOW TO PRIORITIZE WORK?

The day I watched Marie Forleo's film separating the important from the urgent, my life changed. Not all remote jobs start fast, but most of them are...

9. HOW DO YOU PREPARE FOR A MEETING AND PREPARE A MEETING? WHAT DO YOU SEE HAPPENING DURING THE MEETING?

Just as communication is essential when working remotely, so is organization. Because you won't have those opportunities in the elevator or a casual conversation in the lunchroom, you should take advantage of the little time you have in a video or phone conference...

10. HOW DO YOU USE TECHNOLOGY ON A DAILY BASIS, IN YOUR WORK AND FOR YOUR PLEASURE?

This is a great question because it shows your comfort level with technology, which is very important for a remote worker because you will be working with technology over time...