27 дней назад
Supply Chain Risk Management (SCRM) Program Lead
232 000 - 273 000$
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Supply Chain Risk Management (SCRM) Program Lead (Security/AI-native): Own Legora’s Supply Chain Risk Management program end to end, with an accent on criticality, resiliency, and exposure across third-party dependencies. Focus on building a living dependency map, running continuous monitoring and evidence gathering with AI agents, and quantifying risk in loss-event terms to drive control funding and contingency decisions.
Company
Legora builds an AI-native workspace that helps legal teams move faster with precise, end-to-end workflows.
What you will do
- Maintain a living dependency map and tier dependencies by real failure impact (not contract value or questionnaire scores).
- Run critical-dependency resiliency analysis: degradation behavior, recovery speed, concentration risk, and exit/contingency planning.
- Assess exposure for each provider: what they can access/reach, data categories, and blast radius; detect use-case drift continuously.
- Operate the full SCRM program: intake, assessments, continuous monitoring, supplier-incident coordination, and off-boarding with risk closure verification.
- Orchestrate AI agents for evidence gathering, drift detection, and triage with human-in-the-loop assurance where needed; automate repetitive work.
- Govern subprocessor risk and report metrics that demonstrate risk reduction (e.g., drift resolved, time to assess, resilience posture).
Requirements
- 6–8+ years in third-party/supply-chain risk, security risk, or related, with experience standing up a program (not only operating one).
- Experience running third-party/supply-chain risk in a SaaS or cloud-native environment, with clear views on where traditional TPRM fails.
- Hands-on automation ability (scripting, APIs, LLM/agent workflows) and experience building pipelines rather than spreadsheets.
- Ability to quantify risk in a way you can defend to a CFO.
- Strong assurance knowledge: SOC 2, ISO 27001, GDPR subprocessor obligations, DORA-style operational resilience, and AI-provider assurance.
- Judgment on AI in the loop: what to delegate to agents, what requires a human, and how to evidence both for auditors.
Culture & Benefits
- On-site role in the Union Square office; company-provided lunch daily.
- Comprehensive benefits including medical/dental/vision options (Aetna, Kaiser Permanente; MetLife; Vision Care) and HSA or Healthcare FSA.
- 401(k) with generous company match, life insurance + STD/LTD, and unlimited PTO.
- Family support: generous parental leave and dependent care FSA; free access to Maven Clinic and One Medical.
- Robust voluntary benefits including identity protection (Aura) and legal coverage via MetLife.
Hiring process
- Interviews focused on program ownership, risk quantification, and how you apply AI agents with human-in-the-loop assurance.
- Discussion of how you would build continuous monitoring and evidence pipelines for third-party dependencies.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →