Lead Cybersecurity Specialist

Other Jobs To Apply

<p><span style="font-size: 12pt;"><strong>About Legence</strong></span><br><span style="font-size: 12pt;"><a rel="noopener" href="https://www.wearelegence.com/" target="_blank">Legence</a> (Nasdaq: LGN) is a leading provider of engineering, consulting, installation, and maintenance services for mission-critical systems in buildings. The company specializes in designing, fabricating, and installing complex HVAC, process piping, and other mechanical, electrical, and plumbing (MEP) systems—enhancing energy efficiency, reliability, and sustainability in new and existing facilities. Legence also delivers long-term performance through strategic upgrades and holistic solutions. Serving some of the world’s most technically demanding sectors, Legence counts over 60% of the Nasdaq-100 Index among its clients.</span></p><p><span style="font-size: 12pt;">Location: Remote, United States. Near Legence office preferred. </span></p> <p><span style="font-size: 12pt;">The Lead Cybersecurity Specialist within the Legence IT Security organization will be responsible for helping advance the company’s overall security posture. This role goes beyond operational support to include architecture, risk strategy, and cross-functional leadership. This role will work with other IT pillars and team members to implement, and continuously improve security controls that protect enterprise systems, cloud environments, and data against evolving threats while aligning with business objectives and regulatory requirements.  This role will provide team leadership to junior staff members </span></p> <p><span style="font-size: 12pt;"> <strong>About the Role </strong></span><br><span style="font-size: 12pt;">We are seeking a highly skilled Lead Cybersecurity Specialist to lead a team of cyber analysts tasked with advancing Legence’s security posture and reducing risk.  This role is critical to ensuring the integrity, reliability, and security of our IT systems and processes. The ideal candidate will bring deep cyber experience, the ability to develop team members, the ability to communicate with business and IT partners, and a focus in ITGC audits, tool selection, continuous improvement, and cross-functional project management. </span></p> <p><span style="font-size: 12pt;"><strong>Key Responsibilities </strong></span></p> <ul> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Cloud Security & Architecture</span> <ul> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Ensure the implementation and governance of secure cloud architectures across platforms.</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Continue development, enforcement, and governance of cyber security controls (including identity, access management, and workload protection).</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Partner with engineering teams to embed security into cloud-native development and DevOps processes (DevSecOps).</span></li> </ul> </li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Enterprise Risk Management</span> <ul> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Evolve the organization’s security risk management program.</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Conduct risk assessments, threat modeling, and control evaluations.</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Translate technical risks into business impact and present recommendations to senior leadership.</span></li> </ul> </li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Security Engineering & Automation</span> <ul> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Develop and maintain advanced automation frameworks and scripts to improve detection, response, and compliance capabilities.</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Lead efforts to integrate security tooling (SIEM, EDR, CSPM, etc.) into a cohesive security ecosystem.</span></li> </ul> </li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Threat Detection & Incident Response</span> <ul> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Oversee monitoring and detection strategies across networks, endpoints, and cloud environments.</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Lead incident response efforts, including triage, containment, root cause analysis, and post-incident improvements.</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Drive continuous improvement of detection use cases and response playbooks.</span></li> </ul> </li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Vulnerability Management & Offensive Security</span> <ul> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Lead vulnerability management lifecycle, including scanning, prioritization, and remediation strategies.</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Coordinate perform penetration testing and adversary simulations.</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Provide expert guidance on remediation and risk prioritization.</span></li> </ul> </li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Governance, Compliance & Security Strategy</span> <ul> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Support and help shape governance, risk, and compliance initiatives (e.g., NIST, ISO, SOC 2).</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Lead security assessments, audits, and third-party risk reviews.</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Contribute to long-term cybersecurity strategy, roadmap planning, and security metrics reporting.</span></li> </ul> </li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Leadership & Collaboration</span> <ul> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Act as a technical mentor and escalation point for junior analysts and engineers.</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Oversee the career development of security team members</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Collaborate with IT, engineering, and business stakeholders to align security initiatives with organizational goals.</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Stay ahead of emerging threats, technologies, and industry trends, bringing proactive recommendations to leadership. </span></li> </ul> </li> </ul> <p><span style="font-size: 12pt;"><strong>Qualifications </strong></span></p> <ul> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent experience).</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">5–10+ years of experience in cybersecurity, with demonstrated progression into senior or lead responsibilities.</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Deep expertise in cloud security, network security, and enterprise security architecture.</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Strong experience with security technologies such as SIEM, EDR, IDS/IPS, firewalls, and encryption.</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Proven experience in risk management, incident response, and vulnerability management.</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Proficiency in scripting or programming (e.g., Python, PowerShell, Bash) for automation and security engineering.</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Experience with security frameworks and compliance standards (e.g., NIST, ISO 27001, CIS).</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Strong analytical, problem-solving, and decision-making skills.</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Excellent communication skills, with the ability to influence technical and non-technical stakeholders. </span></li> </ul> <p><span style="font-size: 12pt;"><strong>Preferred Qualifications </strong></span></p> <ul> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Industry certifications such as CISSP, CISM, CCSP, or GIAC.</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Experience leading security initiatives or small teams. </span></li> </ul> <p><span style="font-size: 12pt;">Compensation: $125k-$165k, depending on experience</span></p> <p><span style="font-size: 12pt;">#LI-JS1 #LI-Remote</span></p><p><strong>Benefits Overview</strong><br><strong>401(k) Plan with Company Match:</strong> Currently match contributions dollar-for-dollar up to 4% of eligible pay; immediate vesting. <br><strong>Health & Welfare Benefits:</strong> Employer provided medical, dental, vision, prescription drug, Employee Assistance Program and accident & illness coverage. <br><strong>Life and Disability Insurance</strong>: Employer provided basic life insurance and AD&D valued at 50K coverage amount with the option for voluntary buy up for additional coverage.<br><strong>Time Off:</strong> Flexible non-accrual vacation; company holidays per policy. <em>(For California employees, this is separate from California paid sick leave, if applicable.)</em><br><strong>Expenses</strong>: Business travel and related expenses reimbursed per company policy.</p> <p><strong>Reasonable Accommodations<br></strong>If you need assistance or accommodations during the application or interview process, please contact us at <a rel="noopener" href="mailto:ta@wearelegence.com" target="_blank" title="mailto:ta@wearelegence.com" data-linkindex="0">ta@wearelegence.com</a> or your dedicated recruiter with the <span data-ogsb="" data-ogsc="" data-ogab="" data-ogac="" data-markjs="true">job</span> title and requisition number.</p> <p><strong>Employment Eligibility</strong><br>Candidates must have current work authorization in the U.S.; visa sponsorship is not available for this position.</p> <p><strong>Third-Party Recruiting Disclaimer</strong><br>Legence and its affiliates do not accept unsolicited resumes from agencies; any such submissions without a prior signed agreement authorized by Legence Holdings LLC's CHRO or Director of Talent Acquisition will not incur fees and are considered property of Legence.</p> <p><strong>Pay Disclosure & Considerations</strong><br>Where pay ranges are indicated, please note that a successful candidate’s exact pay will be determined based relevant <span data-ogsb="" data-ogsc="" data-ogab="" data-ogac="" data-markjs="true">job</span>-related factors, including any of the following: candidate’s experience, skills, and qualifications, as well as geographic and market considerations.  We are committed to ensuring fair and competitive compensation for all employees and comply with all applicable salary transparency laws. </p> <p><span style="font-size: 8pt;"><strong>Equal Employment Opportunity Employer<br></strong>Legence and its affiliate companies are proud to be an equal opportunity workplace. We are committed to equal employment opportunity regardless of race, color, religion, sex (including pregnancy, gender identity, and sexual orientation), marital or familial status, national origin, age, disability, genetic information (including family medical history), political affiliation, military service, other non-merit-based factors, and any other characteristic protected under applicable local, state or federal laws and regulations.</span><br><span style="font-size: 8pt;"><a rel="noopener" href="https://nam11.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.eeoc.gov%2Femployers%2Feeo-law-poster&data=05%7C02%7CDivya.Selvaraj%40wearelegence.com%7C492534f848704ab3d99108dd578322ed%7C7bb63ee7a3e14d75b5a56f9549f171a3%7C0%7C0%7C638762942911616035%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=1wutgP6pyxZg1OBPthpEEp1LqTFttzm9dDo6Kpdx88M%3D&reserved=0" target="_blank" title="Original URL: https://www.eeoc.gov/employers/eeo-law-poster. Click or tap if you trust this link." data-linkindex="1" data-auth="NotApplicable">EEO is the Law</a> </span></p>

Back to blog