Supply Chain Risk Lead

Legora

$120K — $150K *
Business Services
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 6-8+ years in third-party/supply chain risk, security risk, or related fields, with an emphasis on program development.
  • Experience managing supply chain risk in a SaaS or cloud-native setting, with insights on the limitations of traditional TPRM.
  • Proven ability to automate processes through scripting, APIs, and LLM workflows.
  • Strong risk quantification skills, able to present findings to C-level executives.
  • Familiarity with assurance standards such as SOC 2, ISO 27001, GDPR, and operational resilience frameworks.
  • Deep understanding of applying AI tools in risk assessment and management.

Responsibilities

  • Own and execute Legora's advanced Supply Chain Risk Management program.
  • Develop and maintain a detailed dependency map highlighting critical paths and failures.
  • Conduct concentration-risk analysis and formulate contingency plans for critical providers.
  • Evaluate the resilience of dependencies and establish recovery protocols.
  • Continuously monitor and assess provider access and compliance to minimize risk exposure.
  • Automate manual tasks to improve monitoring and risk assessments using AI agents.
  • Report measurable risk reductions and program effectiveness to leadership.

Benefits

  • Global collaboration with teams and clients across multiple continents.
  • Comprehensive salary and benefits package.
  • Meaningful work influencing how legal professionals leverage AI.
  • Dynamic in-person work environment with provided daily lunches.
  • Medical, dental, and vision plan options through reputable providers with HSA/FSA options.
  • Generous parental leave and family health support initiatives.
  • 401(K) plan with a substantial company match and unlimited PTO.
Full Job Description
The Role

You will own Legora's Supply Chain Risk Management program end to end. This is deliberately not a traditional TPRM role. TPRM asks "did the vendor answer our questions?", questionnaire, tier, file the SOC 2, reassess in twelve months. SCRM asks "which dependencies can hurt us, how badly, and what do we control about it?" Every assessment you produce should change a decision: which control gets funded, which dependency gets a contingency plan, which vendor gets dropped.

You will sit in the Security organization and run the program the way an AI-native company should: AI agents handle the repetitive work, your time goes to judgment. The program is built on three lenses applied to every provider we depend on: criticality, resiliency, and exposure.

What You'll Do

Criticality
  • Maintain a living dependency map: what sits in the critical path, what is a single point of failure, what depends on what (fourth parties included). The map derives from the SaaS Enablement & Governance Lead's portfolio system of record, one inventory, two lenses.
  • Tier dependencies by what actually breaks when a provider fails, not by contract value or questionnaire score.

Resiliency
  • Answer, for every critical dependency: what happens when it degrades, and how fast do we recover?
  • Own concentration-risk analysis, exit and contingency plans, and resilience requirements that shape architecture and procurement before a provider is adopted.

Exposure
  • Know what each provider can see, touch, and reach, data categories, access paths, blast radius.
  • Detect use-case drift continuously: new integrations, new data types, access that doesn't match the approved use.

Program and automation
  • Run the program: intake, assessment, continuous monitoring, supplier-incident coordination, off-boarding.
  • Work the seam with the SaaS Enablement & Governance Lead: intake arrives through their front door and your requirements gate adoption; they enforce those requirements commercially in contracts and renewals; on off-boarding they execute teardown and you verify risk closure for critical vendors.
  • Orchestrate AI agents for evidence gathering, drift detection, and triage, with human-in-the-loop where assurance demands it. Anything manual twice a quarter gets automated.
  • Prioritize first-party mitigations: we can't change a vendor's controls, but we can scope access, restrict egress, and minimize data on our side.
  • Express supply chain risk in loss-event terms (FAIR or similar) so leadership can compare it against other investments, no heat-maps with 18 risks in the yellow square.
  • Own subprocessor governance: the register, customer notification commitments, and the assurance story we give law-firm security teams.
  • Report metrics that show risk reduction, not activity: drift caught and resolved, time to assess, resilience posture of critical dependencies.

What You Bring
  • 6-8+ years in third-party/supply-chain risk, security risk, or related, with weight given to candidates who have stood up a program (not just run one).
  • Experience running third-party or supply chain risk in a SaaS or cloud-native environment, with clear opinions on where traditional TPRM fails.
  • Hands-on automation ability: scripting, APIs, LLM/agent workflows. Pipelines, not spreadsheets.
  • Risk quantification you can defend to a CFO.
  • Fluency in the assurance landscape our customers care about: SOC 2, ISO 27001, GDPR subprocessor obligations, DORA-style operational resilience, and AI-provider assurance (model providers are supply chain too).
  • Judgment on AI in the loop, grounded in daily use of AI tools in your own work: what to delegate to agents, what needs a human, and how to evidence both to an auditor.

Nice to have
  • Experience assessing AI/LLM providers as dependencies: model change management, training-data terms, availability commitments.
  • Standing up continuous monitoring or a risk-operations function from scratch.
  • Experience in legal tech, fintech, or another high-trust B2B environment.


What's In It For You
  • Global collaboration: Partner with teams and clients across Europe, APAC, and North America.
  • Competitive package: Comprehensive salary, benefits, and tools for success.
  • Meaningful work: Your efforts shape how thousands of lawyers use AI daily.
  • In-person environment: Union Square office designed for ambitious builders and company provided lunch daily.
  • Benefits & Perks: We invest in our people with a comprehensive, thoughtfully designed benefits package:
    Medical, Dental & Vision
    • Multiple medical plan options through Aetna and Kaiser Permanente
    • HSA or Healthcare FSA (based on plan selection)
    • Dental plans via MetLife
    • Vision plans via Vision Care

    Family Support
    • Generous parental leave
    • Free access to Maven Clinic
    • Dependent Care FSA
    • Free One Medical membership for employees and dependents

    Additional Perks
    • Pre-tax commuter benefits
    • Life Insurance + STD/LTD
    • 401(K) with generous company match
    • Unlimited PTO
    • Robust voluntary benefits, including identity protection (via Aura), legal coverage via MetLife, pet savings programs, and more

Similar Jobs

More Jobs at Legora

More Business Services Jobs

Find similar Supply Chain Risk Lead jobs: