Staff Security Engineer

Ambience Healthcare, Inc.

San Francisco, Northern (CA, KY)

Hybrid

USD 226,000 - 283,000

Full time

4 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Equity grant

Job summary

Ambience Healthcare, Inc. is seeking a senior product security engineer to design, build, and operate secure products within security-sensitive healthcare environments.

You’ll own threat models, security requirements, and tooling while guiding high-risk changes and cloud-related security work. You’ll work with engineering from design through verification, applying deep CS fundamentals, security engineering, and AI-augmented practices to reduce risk across production systems and enterprise AI

Qualifications

  • 8+ years of experience in product security, with independent, senior-level judgment.
  • Strong engineering background with production code experience in backend or automation languages.
  • Deep understanding of authentication/authorization (OAuth, OIDC, SAML, JWT, RBAC, ReBAC) and API security.
  • Cloud security fluency across IAM, network, secrets, logging, and CNAPP concepts.
  • Ability to model threats, perform secure code review, and manage multi-tenant SaaS security.

Responsibilities

  • Design secure systems for high-risk changes from proposal to verification.
  • Own security backlog from reviews, tests, audits, and cloud tooling; drive risk to resolution.
  • Develop and own security tooling, automation, and integration improvements.
  • Lead AWS migration security initiatives including IAM and network segmentation.
  • Scope and remediate incidents and turn lessons into durable secure paths.

Skills

Staff-level security judgment
Engineering roots
Authentication & authorization
Cloud security
Threat modeling
Vulnerability testing
Security tooling ownership
AI-augmented security

Tools

Go
Python
Java
TypeScript

Job description

About Us:

Here at Ambience, we never set out to be just another scribe. We're building the AI intelligence platform that restores humanity to healthcare and drives meaningful ROI for health systems across the country.

Our technology helps providers focus on delivering great care by removing the administrative burden that pulls them away from patients and away from their most impactful work. Ambience delivers real-time coding-aware documentation and clinical workflow support across ambulatory, emergency and inpatient settings at the top health systems in North America.

Our teams operate relentlessly with extreme ownership to build the best solutions for our health system partners. We value candor, positivity and deep thought - and we expect a lot from each other because we know the problems we're solving truly matter.

Ambience was ranked #1 for Improving the Clinician Experience in the KLAS Research Emerging Solutions Top 20 Report, recognized by Fast Company as one of the Next Big Things in Tech, named one of the best AI companies in healthcare by Inc., and selected as a LinkedIn Top Startup in 2024 and 2025. We're backed by Oak HC/FT, Andreessen Horowitz (a16z), OpenAI Startup Fund, and Kleiner Perkins - and we're just getting started.

The Role:

Ambience runs real-time clinical workflows inside some of the country’s most security-sensitive health systems. Security can't be bolted on - it must be engineered into the product.

This is a senior technical role focused on how Ambience designs, builds, and operates secure products. You'll bring deep product security expertise and a strong software engineering foundation while extending your impact into cloud security as our AWS environment evolves.

You’ll partner with engineering from design through verification on high-risk changes and foundational product capabilities. You'll own security analysis, technical requirements, risk decisions, and tooling - and contribute code wherever it creates the most leverage.

You’ll design secure systems, work fluently with code, and use AI to build context quickly, accelerate learning, and extend your reach – while grounding every decision in strong computer science, security fundamentals, and technical judgment.

What You’ll Own:

Secure design for high-risk changes — Guide initiatives from design proposals and architecture decisions through implementation and verification. Define threat models and security requirements, review sensitive implementation paths, and contribute prototypes, automation, or PRs when needed.

A credible, risk-based security backlog — Own findings from product reviews, bug bounty, penetration tests, audits, cloud tooling, and hands-on testing. Validate impact, recommend practical mitigations, and drive material issues to verified resolution or explicit risk acceptance.

Security engineering that scales — Expand coverage through guidance, developer enablement, automation, and well-operated tooling. Own tools across integration, tuning, triage, maintenance, and measurement—improve or retire those that aren’t reducing risk.

Cloud risk reduction through our AWS migration — Partner with Platform and Infrastructure Engineering to reduce risk across IAM, network segmentation, workload isolation, secrets, logging, and configuration. Apply strong security fundamentals while building deeper AWS expertise, operationalizing our CNAPP, and establishing practical guardrails.

Security across the environment — Reduce risk across production, development, software delivery, enterprise AI, and internal systems. Help scope and remediate incidents, then turn lessons learned into durable improvements and secure paved paths.

Who You Are:

Staff-level product security judgment. You have the depth to operate independently across complex product security challenges - typically developed through 8+ years of experience and the range to extend into adjacent areas such as cloud security. You don't just find vulnerabilities; you design systems that prevent entire classes of them.

Engineering roots. You've shipped production code, built meaningful software or automation recently, and are strong in at least one backend or automation language such as Go, Python, Java, or TypeScript. You see security as an engineering problem, not a compliance checklist.

Product security depth. You understand authentication and authorization—including OAuth, OIDC, SAML, JWT, RBAC, and ReBAC as well as API security, threat modeling, secure code review, vulnerability testing, and multi-tenant SaaS handling sensitive data. You can move from an architecture diagram into the implementation path that matters.

Cloud security fluency or aptitude. You have working knowledge of cloud security concepts such as IAM, network architecture, workload isolation, secrets, and logging—or a demonstrated ability to develop that expertise quickly.

Offensive validation instincts. You can reproduce vulnerabilities, conduct targeted dynamic testing, build proof-of-concept exploits, and distinguish exploitable risk from theoretical concern.

Demonstrated influence. You've helped engineering teams understand, prioritize, remediate, and verify material security risks.

Tooling ownership. You've owned security tooling or automation beyond deployment, including integration, tuning, triage, maintenance, and evaluation.

AI-augmented security engineering. You use AI as a force multiplier to develop depth in unfamiliar domains, expand your coverage, and move with greater speed. You validate its output against first principles and remain accountable for every technical and security decision.

Based in the Bay Area and able to work from our San Francisco office three days per week.

Nice to Have
  • Experience securing healthcare systems, PHI, or similarly regulated data
  • Experience designing or securing relationship-based or fine-grained authorization systems
  • Offensive security or red-team depth used to demonstrate impact and influence priorities
  • Experience securing enterprise AI applications, AI-enabled products, or internal AI adoption
  • Deep AWS security experience, including IAM, network architecture, workload isolation, configuration management, and CNAPP operations
Why Ambience

At most companies, security is reactive. At Ambience, it is a product enabler. The systems you build will help us earn and keep the trust of the country’s largest health systems.

You’ll have meaningful ownership, direct access to leadership, and the opportunity to define product security at a company where it truly matters. You’ll join a small, high-trust team working on technically deep, mission-critical problems.

Pay Transparency

Every offer at Ambience includes both base salary and an equity grant. The base salary range for this role is:

  • (SF Bay Area): approximately $226k - $283k per year

This intentionally broad range provides flexibility for candidates to tailor their cash and equity mix based on individual preferences. Our compensation philosophy prioritizes meaningful equity grants, enabling team members to share directly in the impact they help create.

Are you outside of the range? We encourage you to still apply: we take an individualized approach to ensure that compensation accounts for all

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff Security Engineer
Staff Security Engineer

Apply • San Francisco (CA), Northern (KY)

Hybrid
USD 226,000 - 283,000
Staff Security Engineer
Staff Security Engineer

Ambience Healthcare • San Francisco (CA)

Hybrid
USD 226,000 - 283,000
Comprehensive medical, dental, vision
401(k) with company match
Remote-friendly culture
+3
Staff Security Engineer
Staff Security Engineer

Socket.dev • San Francisco (CA)

Hybrid
USD 226,000 - 283,000
Medical, dental, vision
401(k) with company match
Remote-friendly culture (SF HQ)
+3
Staff Security Engineer
Staff Security Engineer

ambiencehealthcare • San Francisco (CA)

On-site
USD 180,000 - 210,000
Staff Software Engineer, Distributed Systems
Staff Software Engineer, Distributed Systems

Ambience • San Francisco (CA)

Hybrid
USD 250,000 - 300,000
Medical, dental, vision coverage
401(k) with company match
Remote-friendly culture with SF HQ
Engineering Manager, Product
Engineering Manager, Product

ambiencehealthcare • San Francisco (CA)

On-site
USD 265,000 - 325,000
Engineering Manager, Product
Engineering Manager, Product

Ambience • San Francisco (CA)

On-site
USD 265,000 - 325,000
Comprehensive medical, dental, and vis
401(k) with company match up to 3%
Remote-friendly culture (SF HQ) and装备
+2
Engineering Manager, Product
Engineering Manager, Product

Ambience Healthcare, Inc. • San Francisco (CA), Northern (KY)

Hybrid
USD 265,000 - 325,000
Remote-friendly culture (SF HQ)
Parental leave
Annual off-sites & team events
+2
Engineering Manager, Product
Engineering Manager, Product

Apply • San Francisco (CA), Northern (KY)

Hybrid
USD 265,000 - 325,000
Remote-friendly culture
Equipment provisioning
Parental leave
+3
Engineering Manager, Product
Engineering Manager, Product

Ambience Healthcare • San Francisco (CA)

On-site
USD 265,000 - 325,000
Medical, dental, vision
401(k)
Remote-friendly culture
+2