Staff Security Engineer

ambiencehealthcare

San Francisco (CA)

On-site

USD 180,000 - 210,000

Full time

4 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Ambience seeks a senior product security engineer to design, build, and operate secure products. You’ll work with engineering from design to verification, focusing on cloud security as our AWS environment evolves, bringing deep product security expertise to bear.

You’ll own security analysis, risk decisions, threat modeling, and tooling, and you’ll contribute code where it creates leverage while grounding every decision in strong CS and security fundamentals.

Qualifications

  • 8+ years of product security experience.
  • Experience shipping production security features and tooling.
  • Ability to design secure systems and prevent vulnerabilities.

Responsibilities

  • Define threat models and security requirements for high-risk changes.
  • Own findings from reviews, audits, and tests, and drive risk reduction.
  • Develop scalable security tooling and automation.
  • Lead collaboration with Platform and Infra for secure cloud migration.
  • Design secure systems and guide implementation from design to verification.

Skills

Staff-level security judgement
Backend/Automation development
OAuth/OIDC/SAML/JWT
Threat modeling
Vulnerability testing
Cloud security concepts

Tools

Go
Python
Java
TypeScript

Job description

About Us:

Here at Ambience, we never set out to be just another scribe. We’re building the AI intelligence platform that restores humanity to healthcare and drives meaningful ROI for health systems across the country.

Our technology helps providers focus on delivering great care by removing the administrative burden that pulls them away from patients and away from their most impactful work. Ambience delivers real-time coding-aware documentation and clinical workflow support across ambulatory, emergency and inpatient settings at the top health systems in North America.

Our teams operate relentlessly with extreme ownership to build the best solutions for our health system partners. We value candor, positivity and deep thought - and we expect a lot from each other because we know the problems we’re solving truly matter.

Ambience was ranked #1 for Improving the Clinician Experience in the KLAS Research Emerging Solutions Top 20 Report, recognized by Fast Company as one of the Next Big Things in Tech, named one of the best AI companies in healthcare by Inc., and selected as a LinkedIn Top Startup in 2024 and 2025. We’re backed by Oak HC/FT, Andreessen Horowitz (a16z), OpenAI Startup Fund, and Kleiner Perkins - and we’re just getting started.

The Role:

Ambience runs real-time clinical workflows inside some of the country’s most security-sensitive health systems. Security can’t be bolted on-it must be engineered into the product.

This is a senior technical role focused on how Ambience designs, builds, and operates secure products. You’ll bring deep product security expertise and a strong software engineering foundation while extending your impact into cloud security as our AWS environment evolves.

You’ll partner with engineering from design through verification on high-risk changes and foundational product capabilities. You’ll own security analysis, technical requirements, risk decisions, and tooling-and contribute code wherever it creates the most leverage.

You’ll design secure systems, work fluently with code, and use AI to build context quickly, accelerate learning, and extend your reach-while grounding every decision in strong computer science, security fundamentals, and technical judgment.

What You'll Own:
  • Secure design for high-risk changes - Guide initiatives from design proposals and architecture decisions through implementation and verification. Define threat models and security requirements, review sensitive implementation paths, and contribute prototypes, automation, or PRs when needed.
  • A credible, risk‑based security backlog - Own findings from product reviews, bug bounty, penetration tests, audits, cloud tooling, and hands‑on testing. Validate impact, recommend practical mitigations, and drive material issues to verified resolution or explicit risk acceptance.
  • Security engineering that scales - Expand coverage through guidance, developer enablement, automation, and well‑operated tooling. Own tools across integration, tuning, triage, maintenance, and measurement-and improve or retire those that aren’t reducing risk.
  • Cloud risk reduction through our AWS migration - Partner with Platform and Infrastructure Engineering to reduce risk across IAM, network segmentation, workload isolation, secrets, logging, and configuration. Apply strong security fundamentals while building deeper AWS expertise, operationalizing our CNAPP, and establishing practical guardrails.
  • Security across the environment - Reduce risk across production, development, software delivery, enterprise AI, and internal systems. Help scope and remediate incidents, then turn lessons learned into durable improvements and secure paved paths.
Who You Are:
  • Staff‑level product security judgement. You have the depth to operate independently across complex product security challenges-typically developed through 8+ years of experience—and the range to extend into adjacent areas such as cloud security. You don’t just find vulnerabilities; you design systems that prevent entire classes of them.
  • Engineering roots. You've shipped production code, built meaningful software or automation recently, and are strong in at least one backend or automation language such as Go, Python, Java, or TypeScript. You see security as an engineering problem, not a compliance checklist.
  • Product security depth. You understand authentication and authorization-including OAuth, OIDC, SAML, JWT, RBAC, and ReBAC-as well as API security, threat modeling, secure code review, vulnerability testing, and multi‑tenant SaaS handling sensitive data. You can move from an architecture diagram into the implementation path that matters.
  • Cloud security fluency or aptitude. You have working knowledge of cloud security concepts such as IAM, network architecture, workload isolation, secrets, and logging-or a demonstrated ability to develop that expertise quickly.
  • Offensive validation instincts. You can reproduce vulnerabilities, conduct targeted dynamic testing, build proof‑of‑concept exploits,
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff Security Engineer
Staff Security Engineer

Apply • San Francisco (CA), Northern (KY)

Hybrid
USD 226,000 - 283,000
Staff Security Engineer
Staff Security Engineer

Ambience Healthcare, Inc. • San Francisco (CA), Northern (KY)

Hybrid
USD 226,000 - 283,000
Equity grant
Staff Security Engineer
Staff Security Engineer

Socket.dev • San Francisco (CA)

Hybrid
USD 226,000 - 283,000
Medical, dental, vision
401(k) with company match
Remote-friendly culture (SF HQ)
+3
Staff Security Engineer
Staff Security Engineer

Ambience Healthcare • San Francisco (CA)

Hybrid
USD 226,000 - 283,000
Comprehensive medical, dental, vision
401(k) with company match
Remote-friendly culture
+3
Staff Security Engineer — Secure AI Health Platform (Remote)
Staff Security Engineer — Secure AI Health Platform (Remote)

Socket.dev • San Francisco (CA)

On-site
USD 226,000 - 283,000
Medical, dental, vision
401(k) with company match
Remote-friendly culture (SF HQ)
+3
Cloud Application Security Engineer
Cloud Application Security Engineer

Tactical Edge • Washington

Hybrid
USD 140,000 - 180,000
Staff Platform Engineer, Security
Staff Platform Engineer, Security

Engg • Denver (CO), Long Beach (CA), San Francisco (CA)

On-site
USD 160,000 - 250,000
Staff Product Security Engineer – Cloud & AI
Staff Product Security Engineer – Cloud & AI

Ambience Healthcare, Inc. • San Francisco (CA), Northern (KY)

Hybrid
USD 226,000 - 283,000
Equity grant
Engineering Manager, Product
Engineering Manager, Product

ambiencehealthcare • San Francisco (CA)

On-site
USD 265,000 - 325,000
Senior Cloud Security Engineer
Senior Cloud Security Engineer

BackOps AI • San Francisco (CA)

Hybrid
USD 150,000 - 210,000
Hybrid work model
Remote-friendly options
Equity opportunity