Jobedly Post a Job

Supply Chain Risk Lead

legora · New York City
Full-timeITLogistics & Supply Chain$111,000–$150,000/yr
Apply on Jobedly ⚡ One-click AI Apply

About the Supply Chain Risk Lead role

Supply Chain Risk Lead positions focus on delivering results in their domain. This page aggregates open Supply Chain Risk Lead roles and what employers typically expect.

ABOUT US Legora is redefining how legal work gets done. Not built for lawyers, built with them. We work alongside the world’s best legal teams, who expect excellence, precision, and speed, and we hold ourselves to the same bar. Our AI-native workspace lets legal professionals move faster, think more clearly, and operate with sharper precision. By analysing thousands of documents in minutes and powering end-to-end workflows, we cut through complexity, teams can focus on what matters: judgment, strategy, and outcomes. 1,000+ customers across 50+ countries trust us, including Cleary Gottlieb, Goodwin, Linklaters, White & Case, Dentons, and Barclays. We’ve scaled to $100M+ in ARR, with teams across Europe, North America and APAC, and continue to expand through acquisitions including Qura, Walter AI and Graceview. We partner with world-class performers: including Aaron Judge and the New York Yankees, Ludvig Åberg (and his caddie), and campaigns featuring Jude Law. Joining Legora means three things. - We lean in: ownership over titles, outcomes over intentions. - We fight for excellence: high standards, direct, ego-free feedback. - We grow together: as a team and with our customers. Mission before ego. Everyone contributes. No one coasts. If you’re driven by impact, pace, and raising the bar. This is the place. THE ROLE You will own Legora's Supply Chain Risk Management program end to end. This is deliberately not a traditional TPRM role. TPRM asks "did the vendor answer our questions?", questionnaire, tier, file the SOC 2, reassess in twelve months. SCRM asks "which dependencies can hurt us, how badly, and what do we control about it?" Every assessment you produce should change a decision: which control gets funded, which dependency gets a contingency plan, which vendor gets dropped. You will sit in the Security organization and run the program the way an AI-native company should: AI agents handle the repetitive work, your time goes to judgment. The program is built on three lenses applied to every provider we depend on: criticality, resiliency, and exposure. What You'll Do Criticality - Maintain a living dependency map: what sits in the critical path, what is a single point of failure, what depends on what (fourth parties included). The map derives from the SaaS Enablement & Governance Lead's portfolio system of record, one inventory, two lenses. - Tier dependencies by what actually breaks when a provider fails, not by contract value or questionnaire score. Resiliency - Answer, for every critical dependency: what happens when it degrades, and how fast do we recover? - Own concentration-risk analysis, exit and contingency plans, and resilience requirements that shape architecture and procurement before a provider is adopted. Exposure - Know what each provider can see, touch, and reach, data categories, access paths, blast radius. - Detect use-case drift continuously: new integrations, new data types, access that doesn't match the approved use. Program and automation - Run the program: intake, assessment, continuous monitoring, supplier-incident coordination, off-boarding. - Work the seam with the SaaS Enablement & Governance Lead: intake arrives through their front door and your requirements gate adoption; they enforce those requirements commercially in contracts and renewals; on off-boarding they execute teardown and you verify risk closure for critical vendors. - Orchestrate AI agents for evidence gathering, drift detection, and triage, with human-in-the-loop where assurance demands it. Anything manual twice a quarter gets automated. - Prioritize first-party mitigations: we can't change a vendor's controls, but we can scope access, restrict egress, and minimize data on our side. - Express supply chain risk in loss-event terms (FAIR or similar) so leadership can compare it against other investments, no heat-maps with 18 risks in the yellow square. - Own subprocessor governance: the register, customer notification commitments, and…

Salary estimate

$111,000 – $150,000/yr
Provided by the employer.

Skills for this role

LeadershipSecurityAutomation

Resume tips for Supply Chain Risk Lead applicants

Interview preparation

Prepare concrete STAR-format stories that show Supply Chain Risk Lead outcomes you drove.

Research the employer's product and recent news before the interview.

Be ready to explain how you'd approach a typical Supply Chain Risk Lead problem end to end.

Have thoughtful questions ready about the team, tools and success metrics.

About legora

legora is actively hiring on Jobedly. Explore their open roles and what it's like to work there.

Apply on Jobedly ⚡ One-click AI Apply

Similar jobs

Companies hiring for similar roles