1

Supply Chain Risk Management Jobs in New York (NOW HIRING)

Supply Chain Risk Lead

New York, NY · On-site

$232K - $273K/yr

The Role You will own Legora's Supply Chain Risk Management program end to end. This is deliberately not a traditional TPRM role. TPRM asks "did the vendor answer our questions?", questionnaire, tier ...

Head of Supply Chain

Manhattan, NY · On-site

$160 - $180/hr

... and risk management. Core Mandate Ensure stock is in, on time, in full, within agreed tolerances ... Own supply chain risk, identifying potential disruptions and implementing mitigation strategies.

Senior Manager Strategic Supply Chain

New York, NY · On-site

$141K - $182K/yr

The Strategic Supply Chain Senior Manager leads end-to-end supply chain strategy, driving network ... Risk Management & Compliance * Build resilience strategies for geopolitical, transportation ...

VP, Global Supply Chain Management

Port Washington, NY · On-site

$196K - $222K/yr

Position Summary The Vice President, Global Supply Chain Management is responsible for the ... chain risk mitigation. Process Excellence, Systems, Technology and Data * Own global supply chain ...

... management - Applying analytical thinking to solve complex supply chain issues - Leading supply chain transformation initiatives - Managing supply chain risk effectively Travel Requirements Up to 60 ...

... management - Applying analytical thinking to solve complex supply chain issues - Leading supply chain transformation initiatives - Managing supply chain risk effectively Travel Requirements Up to 60 ...

Responsible for the Supply Chain labor and material cost, schedule, quality, and risk management of assigned programs. * Understand/Report/Influence Supply Chain Program KPIs. * Manage releationships ...

next page

Showing results 1-20

Supply Chain Risk Management information

See New York salary details

$44.3K

$109.7K

$159.7K

How much do supply chain risk management jobs pay per year?

As of Aug 11, 2026, the average yearly pay for supply chain risk management in New York is $109,748.00, according to ZipRecruiter salary data. Most workers in this role earn between $87,500.00 and $131,300.00 per year, depending on experience, location, and employer.

What does a supply chain risk management do?

A supply chain risk management professional identifies and assesses potential disruptions in the supply chain, such as supplier failures, natural disasters, or geopolitical issues. They develop strategies to mitigate these risks, ensuring continuity and resilience in supply operations, often using tools like risk assessment software and data analysis. This role requires strong analytical skills and knowledge of supply chain processes.

What are the most common challenges faced in supply chain risk management?

Supply Chain Risk Management professionals frequently deal with challenges such as disruptions from geopolitical events, natural disasters, supplier reliability issues, and fluctuating market conditions. Balancing cost efficiency with resilience, maintaining real-time visibility across complex networks, and coordinating responses among multiple internal and external partners are also key aspects of the job. You may need to anticipate and respond quickly to risks, requiring both analytical forecasting and decisive action under pressure. Overcoming these challenges involves continuous monitoring, adaptation of strategies, and effective cross-departmental collaboration, which can make the work dynamic and rewarding for those who enjoy problem-solving in fast-paced environments.

What is supply chain risk management?

A Supply Chain Risk Management job involves identifying, assessing, and mitigating risks that could disrupt the supply chain. Professionals in this role analyze potential threats such as supplier failures, geopolitical issues, cybersecurity risks, and natural disasters. They develop contingency plans, implement risk mitigation strategies, and work with suppliers and internal teams to ensure business continuity. The goal is to minimize disruptions, optimize resilience, and protect the organization's operational and financial performance.

What are the key skills and qualifications needed to thrive in supply chain risk management?

To thrive in Supply Chain Risk Management, you need strong analytical skills, an understanding of logistics and risk assessment, and a relevant bachelor's degree (such as supply chain management, business, or engineering). Familiarity with ERP systems, risk analysis software, and certifications like Certified Supply Chain Professional (CSCP) or Certified in Risk and Information Systems Control (CRISC) are commonly required. Excellent problem-solving abilities, effective communication, and adaptability help you collaborate with various stakeholders and navigate changing circumstances. These skills are vital for proactively identifying, evaluating, and mitigating risks to ensure stable and resilient supply chain operations.

Infographic showing various Supply Chain Risk Management job openings in New York as of August 2026, with employment types broken down into 84% Full Time, 8% Temporary, and 8% Contract. Highlights an 100% In-person job distribution, with an average salary of $109,748 per year, or $52.8 per hour.

Supply Chain Risk Lead

Legora

New York, NY • On-site

$232K - $273K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 20 days ago


Job description

About Us
Legora is redefining how legal work gets done. Not built for lawyers, built with them. We work alongside the world's best legal teams, who expect excellence, precision, and speed, and we hold ourselves to the same bar.
Our AI-native workspace lets legal professionals move faster, think more clearly, and operate with sharper precision. By analysing thousands of documents in minutes and powering end-to-end workflows, we cut through complexity, teams can focus on what matters: judgment, strategy, and outcomes.
1,000+ customers across 50+ countries trust us, including Cleary Gottlieb, Goodwin, Linklaters, White & Case, Dentons, and Barclays. We've scaled to $100M+ in ARR, with teams across Europe, North America and APAC, and continue to expand through acquisitions including Qura, Walter AI and Graceview.
We partner with world-class performers: including Aaron Judge and the New York Yankees, Ludvig Åberg (and his caddie), and campaigns featuring Jude Law.
Joining Legora means three things.
  • We lean in: ownership over titles, outcomes over intentions.
  • We fight for excellence: high standards, direct, ego-free feedback.
  • We grow together: as a team and with our customers.

Mission before ego. Everyone contributes. No one coasts.
If you're driven by impact, pace, and raising the bar. This is the place.
The Role
You will own Legora's Supply Chain Risk Management program end to end. This is deliberately not a traditional TPRM role. TPRM asks "did the vendor answer our questions?", questionnaire, tier, file the SOC 2, reassess in twelve months. SCRM asks "which dependencies can hurt us, how badly, and what do we control about it?" Every assessment you produce should change a decision: which control gets funded, which dependency gets a contingency plan, which vendor gets dropped.
You will sit in the Security organization and run the program the way an AI-native company should: AI agents handle the repetitive work, your time goes to judgment. The program is built on three lenses applied to every provider we depend on: criticality, resiliency, and exposure.
What You'll Do
Criticality
  • Maintain a living dependency map: what sits in the critical path, what is a single point of failure, what depends on what (fourth parties included). The map derives from the SaaS Enablement & Governance Lead's portfolio system of record, one inventory, two lenses.
  • Tier dependencies by what actually breaks when a provider fails, not by contract value or questionnaire score.

Resiliency
  • Answer, for every critical dependency: what happens when it degrades, and how fast do we recover?
  • Own concentration-risk analysis, exit and contingency plans, and resilience requirements that shape architecture and procurement before a provider is adopted.

Exposure
  • Know what each provider can see, touch, and reach, data categories, access paths, blast radius.
  • Detect use-case drift continuously: new integrations, new data types, access that doesn't match the approved use.

Program and automation
  • Run the program: intake, assessment, continuous monitoring, supplier-incident coordination, off-boarding.
  • Work the seam with the SaaS Enablement & Governance Lead: intake arrives through their front door and your requirements gate adoption; they enforce those requirements commercially in contracts and renewals; on off-boarding they execute teardown and you verify risk closure for critical vendors.
  • Orchestrate AI agents for evidence gathering, drift detection, and triage, with human-in-the-loop where assurance demands it. Anything manual twice a quarter gets automated.
  • Prioritize first-party mitigations: we can't change a vendor's controls, but we can scope access, restrict egress, and minimize data on our side.
  • Express supply chain risk in loss-event terms (FAIR or similar) so leadership can compare it against other investments, no heat-maps with 18 risks in the yellow square.
  • Own subprocessor governance: the register, customer notification commitments, and the assurance story we give law-firm security teams.
  • Report metrics that show risk reduction, not activity: drift caught and resolved, time to assess, resilience posture of critical dependencies.

What You Bring
  • 6-8+ years in third-party/supply-chain risk, security risk, or related, with weight given to candidates who have stood up a program (not just run one).
  • Experience running third-party or supply chain risk in a SaaS or cloud-native environment, with clear opinions on where traditional TPRM fails.
  • Hands-on automation ability: scripting, APIs, LLM/agent workflows. Pipelines, not spreadsheets.
  • Risk quantification you can defend to a CFO.
  • Fluency in the assurance landscape our customers care about: SOC 2, ISO 27001, GDPR subprocessor obligations, DORA-style operational resilience, and AI-provider assurance (model providers are supply chain too).
  • Judgment on AI in the loop, grounded in daily use of AI tools in your own work: what to delegate to agents, what needs a human, and how to evidence both to an auditor.

Nice to have
  • Experience assessing AI/LLM providers as dependencies: model change management, training-data terms, availability commitments.
  • Standing up continuous monitoring or a risk-operations function from scratch.
  • Experience in legal tech, fintech, or another high-trust B2B environment.

What's In It For You
  • Global collaboration: Partner with teams and clients across Europe, APAC, and North America.
  • Competitive package: Comprehensive salary, benefits, and tools for success.
  • Meaningful work: Your efforts shape how thousands of lawyers use AI daily.
  • In-person environment: Union Square office designed for ambitious builders and company provided lunch daily.
  • Benefits & Perks: We invest in our people with a comprehensive, thoughtfully designed benefits package:
    Medical, Dental & Vision
    • Multiple medical plan options through Aetna and Kaiser Permanente
    • HSA or Healthcare FSA (based on plan selection)
    • Dental plans via MetLife
    • Vision plans via Vision Care

    Family Support
    • Generous parental leave
    • Free access to Maven Clinic
    • Dependent Care FSA
    • Free One Medical membership for employees and dependents

    Additional Perks
    • Pre-tax commuter benefits
    • Life Insurance + STD/LTD
    • 401(K) with generous company match
    • Unlimited PTO
    • Robust voluntary benefits, including identity protection (via Aura), legal coverage via MetLife, pet savings programs, and more

Legora is an Equal Opportunity Employer
At Legora, we believe great teams are built on diversity of thought and experience. We're proud to be an equal opportunity employer and committed to creating an inclusive, high-performance culture where everyone can do their best work. We welcome people of all backgrounds and don't discriminate based on race, color, religion, national origin, gender, gender identity or expression, sexual orientation, age, disability, veteran status, or any other characteristic protected by law.