Назад
27 дней назад

Supply Chain Risk Management (SCRM) Program Lead

232 000 - 273 000$
Формат работы
onsite
Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Supply Chain Risk Management (SCRM) Program Lead (Security/AI-native): Own Legora’s Supply Chain Risk Management program end to end, with an accent on criticality, resiliency, and exposure across third-party dependencies. Focus on building a living dependency map, running continuous monitoring and evidence gathering with AI agents, and quantifying risk in loss-event terms to drive control funding and contingency decisions.

Company

Legora builds an AI-native workspace that helps legal teams move faster with precise, end-to-end workflows.

What you will do

  • Maintain a living dependency map and tier dependencies by real failure impact (not contract value or questionnaire scores).
  • Run critical-dependency resiliency analysis: degradation behavior, recovery speed, concentration risk, and exit/contingency planning.
  • Assess exposure for each provider: what they can access/reach, data categories, and blast radius; detect use-case drift continuously.
  • Operate the full SCRM program: intake, assessments, continuous monitoring, supplier-incident coordination, and off-boarding with risk closure verification.
  • Orchestrate AI agents for evidence gathering, drift detection, and triage with human-in-the-loop assurance where needed; automate repetitive work.
  • Govern subprocessor risk and report metrics that demonstrate risk reduction (e.g., drift resolved, time to assess, resilience posture).

Requirements

  • 6–8+ years in third-party/supply-chain risk, security risk, or related, with experience standing up a program (not only operating one).
  • Experience running third-party/supply-chain risk in a SaaS or cloud-native environment, with clear views on where traditional TPRM fails.
  • Hands-on automation ability (scripting, APIs, LLM/agent workflows) and experience building pipelines rather than spreadsheets.
  • Ability to quantify risk in a way you can defend to a CFO.
  • Strong assurance knowledge: SOC 2, ISO 27001, GDPR subprocessor obligations, DORA-style operational resilience, and AI-provider assurance.
  • Judgment on AI in the loop: what to delegate to agents, what requires a human, and how to evidence both for auditors.

Culture & Benefits

  • On-site role in the Union Square office; company-provided lunch daily.
  • Comprehensive benefits including medical/dental/vision options (Aetna, Kaiser Permanente; MetLife; Vision Care) and HSA or Healthcare FSA.
  • 401(k) with generous company match, life insurance + STD/LTD, and unlimited PTO.
  • Family support: generous parental leave and dependent care FSA; free access to Maven Clinic and One Medical.
  • Robust voluntary benefits including identity protection (Aura) and legal coverage via MetLife.

Hiring process

  • Interviews focused on program ownership, risk quantification, and how you apply AI agents with human-in-the-loop assurance.
  • Discussion of how you would build continuous monitoring and evidence pipelines for third-party dependencies.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →