SlipstreamJobsFresh Startup & VC-Backed Jobs

Staff Security Engineer

Ambience Healthcare - San Francisco, CA, United States - Hybrid - posted 2026-09-18

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 226,000 - 283,000 / annual

Ambience Healthcare is building an AI intelligence platform that restores humanity to healthcare by removing administrative burden from clinicians. The company delivers real-time, coding-aware documentation and clinical workflow support across ambulatory, emergency, and inpatient settings at top health systems in North America. Backed by leading VCs including Andreessen Horowitz and OpenAI Startup Fund, Ambience has been recognized as #1 for Improving Clinician Experience by KLAS Research and named a LinkedIn Top Startup. In this Staff-level security engineering role, you will own product security architecture and cloud security strategy for a company operating in highly regulated healthcare environments. You'll partner with engineering teams from design through verification on high-risk changes and foundational product capabilities. Your responsibilities include: **Core Ownership Areas:** - Secure design for high-risk changes: Guide initiatives from design proposals and architecture decisions through implementation and verification. Define threat models, security requirements, review sensitive implementation paths, and contribute code or automation when needed. - Risk-based security backlog: Own findings from product reviews, bug bounty, penetration tests, audits, and cloud tooling. Validate impact, recommend practical mitigations, and drive material issues to resolution or explicit risk acceptance. - Security engineering at scale: Expand coverage through developer enablement, automation, and well-operated tooling. Own tools across integration, tuning, triage, maintenance, and measurement. - AWS cloud risk reduction: Partner with Platform and Infrastructure Engineering to reduce risk across IAM, network segmentation, workload isolation, secrets, logging, and configuration. Operationalize CNAPP and establish practical guardrails. - Environment-wide security: Reduce risk across production, development, software delivery, enterprise AI, and internal systems. Help scope and remediate incidents, turning lessons learned into durable improvements. You'll work in a high-ownership, high-trust environment with meaningful autonomy, direct access to leadership, and the opportunity to define product security at a company where it truly matters. The role requires three days per week in the San Francisco office. **Requirements:** - 8+ years of experience with staff-level product security judgment, operating independently across complex product security challenges - Strong engineering foundation: shipped production code, built meaningful software or automation recently, strong in at least one backend or automation language (Go, Python, Java, TypeScript) - Deep product security expertise: authentication and authorization (OAuth, OIDC, SAML, JWT, RBAC, ReBAC), API security, threat modeling, secure code review, vulnerability testing, multi-tenant SaaS handling sensitive data - Cloud security fluency or demonstrated aptitude: working knowledge of IAM, network architecture, workload isolation, secrets, logging, or ability to develop expertise quickly - Offensive validation instincts: ability to reproduce vulnerabilities, conduct targeted dynamic testing, build proof-of-concept exploits, distinguish exploitable risk from theoretical concern - Demonstrated influence: helped engineering teams understand, prioritize, remediate, and verify material security risks - Tooling ownership: owned security tooling or automation beyond deployment, including integration, tuning, triage, maintenance, and evaluation - AI-augmented security engineering: use AI as a force multiplier to develop depth in unfamiliar domains, expand coverage, and move with greater speed while validating output against first principles **Nice to Have:** - Experience securing healthcare systems, PHI, or similarly regulated data - Experience designing or securing relationship-based or fine-grained authorization systems - Offensive security or red-team depth - Experience securing enterprise AI applications or AI-enabled products - Deep AWS security experience including IAM, network architecture, workload isolation, configuration management, and CNAPP operations

Similar roles