SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Ambience Healthcare is an AI-powered healthcare platform that delivers real-time, coding-aware clinical documentation and workflow support to health systems across North America. The company has been recognized as #1 for Improving Clinician Experience by KLAS Research and is backed by leading investors including Andreessen Horowitz, OpenAI Startup Fund, and Kleiner Perkins.
You will own the governance, risk, and compliance program end-to-end as a senior individual contributor with broad mandate and real latitude to shape how the program operates. This is a hands-on role where you'll treat GRC as an agile, evolving practice rather than a checkbox exercise, using AI coding tools like Claude Code to answer compliance questions directly from the codebase.
Key responsibilities include:
- Own the SOC 2 compliance program end-to-end: manage auditor relationships, evidence collection and interpretation in Vanta, and maintain continuous audit readiness as infrastructure evolves. Help establish AI governance frameworks like ISO 42001.
- Build and maintain PHI governance: Create an authoritative inventory of where Protected Health Information lives, which systems and models touch it, and identify and close HIPAA and governance gaps.
- Investigate controls hands-on: Use AI coding assistants to verify whether controls (e.g., encryption at rest) are actually implemented, producing clear, evidenced answers without requiring engineering hand-holding.
- Establish vendor and AI-model risk reviews: Build and run the security review process for new vendors and AI model providers, partnering with legal and finance to document risk assessments.
- Drive risk remediation: Partner with engineering to enumerate, prioritize, and remediate security risks on a predictable, auditable cadence. Author security and compliance policies that engineering, legal, and GTM teams can actually follow.
- Serve as the front door for customer trust: Handle RFPs and security questionnaires, maintain a trust portal with current customer-facing evidence.
The role operates in a high-ownership, high-trust environment where you'll have meaningful autonomy, work on mission-critical technology that improves clinician workflows, and operate as part of a championship team culture.
REQUIREMENTS:
- Senior-level GRC or compliance experience in a SaaS environment, including owning a SOC 2 (or equivalent) audit from evidence collection through auditor sign-off, ideally using a GRC automation platform like Vanta or Drata.
- Technical curiosity and comfort using AI coding tools like Claude Code to answer compliance questions directly from source code (you won't need to write code yourself). Ability to threat-model new vendors: understanding what data they touch, where data flows, and what controls are needed.
- Clear writing and communication skills. You write policies and standards that hold up to audit and that engineers can actually use. You work directly and confidently with engineering, legal, and customers.
- Startup ownership mindset: thrive in ambiguity, take a partially built function and make it accountable without waiting for structure, and work outside a narrow swim lane.
Nice-to-have qualifications:
- ISO 27001 experience and exposure to ISO 42001 or other AI governance frameworks.
- Background in regulated industries such as healthcare, fintech, or other highly regulated sectors.