Level

Ambience HealthcarePosted today

L1

Staff Security Engineer

Staff Security Engineer at Ambience Healthcare scores 20 out of 100 on AI centrality, which makes it a Level 1 role on this board.

San FranciscoseniorFullTime$226k-$283k

AI in this role

Staff Security Engineer focused on securing healthcare AI platform products and cloud infrastructure.

openaiaws
product-securitycloud-securitythreat-modelingsecurity-analysis

About Us:

Here at Ambience, we never set out to be just another scribe. We’re building the AI intelligence platform that restores humanity to healthcare and drives meaningful ROI for health systems across the country.

Our technology helps providers focus on delivering great care by removing the administrative burden that pulls them away from patients and away from their most impactful work. Ambience delivers real-time coding-aware documentation and clinical workflow support across ambulatory, emergency and inpatient settings at the top health systems in North America.

Our teams operate relentlessly with extreme ownership to build the best solutions for our health system partners. We value candor, positivity and deep thought — and we expect a lot from each other because we know the problems we’re solving truly matter.

Ambience was ranked #1 for Improving the Clinician Experience in the KLAS Research Emerging Solutions Top 20 Report, recognized by Fast Company as one of the Next Big Things in Tech, named one of the best AI companies in healthcare by Inc., and selected as a LinkedIn Top Startup in 2024 and 2025. We’re backed by Oak HC/FT, Andreessen Horowitz (a16z), OpenAI Startup Fund, and Kleiner Perkins — and we’re just getting started.

The Role:

Ambience runs real-time clinical workflows inside some of the country’s most security-sensitive health systems. Security can’t be bolted on—it must be engineered into the product.

This is a senior technical role focused on how Ambience designs, builds, and operates secure products. You’ll bring deep product security expertise and a strong software engineering foundation while extending your impact into cloud security as our AWS environment evolves.

You’ll partner with engineering from design through verification on high-risk changes and foundational product capabilities. You’ll own security analysis, technical requirements, risk decisions, and tooling—and contribute code wherever it creates the most leverage.

You’ll design secure systems, work fluently with code, and use AI to build context quickly, accelerate learning, and extend your reach—while grounding every decision in strong computer science, security fundamentals, and technical judgment.

What You’ll Own:

Secure design for high-risk changes — Guide initiatives from design proposals and architecture decisions through implementation and verification. Define threat models and security requirements, review sensitive implementation paths, and contribute prototypes, automation, or PRs when needed.

A credible, risk-based security backlog — Own findings from product reviews, bug bounty, penetration tests, audits, cloud tooling, and hands-on testing. Validate impact, recommend practical mitigations, and drive material issues to verified resolution or explicit risk acceptance.

Security engineering that scales — Expand coverage through guidance, developer enablement, automation, and well-operated tooling. Own tools across integration, tuning, triage, maintenance, and measurement—and improve or retire those that aren’t reducing risk.

Cloud risk reduction through our AWS migration — Partner with Platform and Infrastructure Engineering to reduce risk across IAM, network segmentation, workload isolation, secrets, logging, and configuration. Apply strong security fundamentals while building deeper AWS expertise, operationalizing our CNAPP, and establishing practical guardrails.

Security across the environment — Reduce risk across production, development, software delivery, enterprise AI, and internal systems. Help scope and remediate incidents, then turn lessons learned into durable improvements and secure paved paths.

Who You Are:

Staff-level product security judgment. You have the depth to operate independently across complex product security challenges—typically developed through 8+ years of experience—and the range to extend into adjacent areas such as cloud security. You don’t just find vulnerabilities; you design systems that prevent entire classes of them.

Engineering roots. You’ve shipped production code, built meaningful software or automation recently, and are strong in at least one backend or automation language such as Go, Python, Java, or TypeScript. You see security as an engineering problem, not a compliance checklist.

Product security depth. You understand authentication and authorization—including OAuth, OIDC, SAML, JWT, RBAC, and ReBAC—as well as API security, threat modeling, secure code review, vulnerability testing, and multi-tenant SaaS handling sensitive data. You can move from an architecture diagram into the implementation path that matters.

Cloud security fluency or aptitude. You have working knowledge of cloud security concepts such as IAM, network architecture, workload isolation, secrets, and logging—or a demonstrated ability to develop that expertise quickly.

Offensive validation instincts. You can reproduce vulnerabilities, conduct targeted dynamic testing, build proof-of-concept exploits, and distinguish exploitable risk from theoretical concern.

Demonstrated influence. You’ve helped engineering teams understand, prioritize, remediate, and verify material security risks.

Tooling ownership. You’ve owned security tooling or automation beyond deployment, including integration, tuning, triage, maintenance, and evaluation.

AI-augmented security engineering. You use AI as a force multiplier to develop depth in unfamiliar domains, expand your coverage, and move with greater speed. You validate its output against first principles and remain accountable for every technical and security decision.

Based in the Bay Area and able to work from our San Francisco office three days per week.

Nice to Have

  • Experience securing healthcare systems, PHI, or similarly regulated data

  • Experience designing or securing relationship-based or fine-grained authorization systems

  • Offensive security or red-team depth used to demonstrate impact and influence priorities

  • Experience securing enterprise AI applications, AI-enabled products, or internal AI adoption

  • Deep AWS security experience, including IAM, network architecture, workload isolation, configuration management, and CNAPP operations

Why Ambience

At most companies, security is reactive. At Ambience, it’s a product enabler. The systems you build will help us earn—and keep—the trust of the country’s largest health systems.

You’ll have meaningful ownership, direct access to leadership, and the opportunity to define product security at a company where it truly matters. You’ll join a small, high-trust team working on technically deep, mission-critical problems.

Pay Transparency

Every offer at Ambience includes both base salary and an equity grant. The base salary range for this role is:

  • (SF Bay Area): approximately $226k — $283k per year

This intentionally broad range provides flexibility for candidates to tailor their cash and equity mix based on individual preferences. Our compensation philosophy prioritizes meaningful equity grants, enabling team members to share directly in the impact they help create.

Are you outside of the range? We encourage you to still apply: we take an individualized approach to ensure that compensation accounts for all of the life factors that matter for each candidate.

Life at Ambience

Working at Ambience means opting into a high-ownership, high-trust environment built for people who want to grow fast, operate decisively and focus on work that matters. This could be the right place for you if you want to

  • Work on mission-critical AI technology that directly improves clinicians’ day-to-day lives and health system financial health across some of the most complex, high-stakes workflows in the world.

  • Join a “dream team” culture where we hire exceptional people, expect exceptional outcomes and invest deeply in feedback and continuous growth. We operate as a championship team, and that means being ok with hard, uncomfortable, ambiguous problems that lead to real greatness.

  • Operate with real ownership and accountability in an environment where there are no bystanders: If something is broken, we fix it! You will have meaningful autonomy and be expected to drive work to completion.

To help you do your best work, we pair these expectations with benefits intentionally designed to help you feel supported and safe at Ambience and beyond. Some of our key benefits include

  • Comprehensive medical, dental, and vision coverage for you and your dependents

  • 401(k) with a company match of up to 3% of base salary

  • A remote-friendly culture (with a San Francisco HQ) and full equipment provisioning to ensure you can work effectively from wherever you’re based.

  • Parental leave to support your family needs

  • Annual company-wide off-sites, team off-sites and regular team lunches and all-hands gatherings, with travel, lodging and meals covered

  • Flexible time off with no annual cap, company-wide holidays and an annual holiday shutdown from December 24–January 1 designed to support real rest and long-term sustainability.

Ambience Healthcare is an equal opportunity employer and is committed to building a diverse and inclusive workplace. We do not discriminate on the basis of race, color, religion, sex, gender identity or expression, sexual orientation, national origin, age, disability, veteran status, genetic information, or any other legally protected status. We encourage applicants from all backgrounds to apply.

Ambience is committed to supporting every candidate’s ability to fully participate in our hiring process. If you need any accommodations during your application or interviews, please reach out to our Recruiting team at [email protected]. We’ll handle your request confidentially and work with you to ensure an accessible and equitable experience for all candidates.


Ambience Healthcare has become aware of scams targeting jobseekers with fake jobs and even interviewing people. Our emails will always come from @ambiencehealthcare.com. We would never our ask candidates to download apps or make any form of payment(s). If you are contacted through WhatsApp, Telegram, similar but fake email domains, or asked to make a payment, these contacts are not legitimate. Report the issue immediately to LinkedIn and the FBI.

L1Liked this Level 1 role? Get the best new ones weekly

Level 1 means “AI is not the work”. Every week we send the highest-scoring new roles, Level 1 included, each rated Level 1 to 4. One email, no recruiter spam.

Free. One useful digest a week. Unsubscribe in one click.

Similar roles

Security roles rated Level 1 at other companies.

More jobs at Ambience Healthcare

Related searches

Same AI level