← Back to results

Staff Security Engineer

Join Ambience as a Staff Security Engineer to design secure systems for healthcare AI technology in a high-trust environment.

Location
San Francisco
Compensation
$226k–$283k/yr
Level
staff
Type
full time · Hybrid

Posted by employer 4 days ago

First seen on Joblaze 3 days ago

Last verified on the company career page 1 day ago

Apply at Ambience Healthcare → Save job Scanned from ambiencehealthcare.com

Skills & Technologies

What you'll build

  • Guide secure design for high-risk changes
  • Own security analysis and technical requirements
  • Expand security engineering coverage
  • Partner with engineering to reduce cloud risk
  • Reduce risk across production and development environments

Must have

  • 8+ years of experience in product security
  • Strong software engineering foundation
  • Experience with backend or automation languages
  • Understanding of authentication and authorization
  • Experience with API security and threat modeling

Nice to have

  • Experience securing healthcare systems
  • Experience designing authorization systems
  • Offensive security or red-team experience
  • Experience securing enterprise AI applications
  • Deep AWS security experience

Practical constraints

  • Based in the Bay Area and able to work from the San Francisco office three days per week

AI in the day-to-day

You use AI as a force multiplier to develop depth in unfamiliar domains, expand your coverage, and move with greater speed.

Requirements

Experience
8+ years

Not disclosed in this posting: visa sponsorship.

Benefits

401k Match Unlimited PTO Equity/Stock Options Remote Work Health Insurance Parental Leave

Joblaze summary

The Staff Security Engineer at Ambience Healthcare is responsible for integrating security into the design and operation of their AI-driven clinical workflows, ensuring robust protection against vulnerabilities. This role requires a strong foundation in software engineering and product security, with a focus on cloud security as the company transitions to AWS. Ideal candidates will have extensive experience in security engineering, particularly in healthcare or regulated environments, and a proactive approach to risk management. Ambience emphasizes a high-ownership culture, where security is viewed as a critical enabler of their mission.

Joblaze insights

  • Listed 3 days ago — first seen on Joblaze September 19, 2026. Last confirmed on Ambience Healthcare's careers page September 21, 2026.
  • Salary band is above the typical range for Security roles (median ~$170,000).
  • Starts above 86% of 35 comparable staff security roles in United States that list Python we track (median $200,000 across 20 companies). See Python salary trends
  • Python appears in 48.8% of 86 comparable staff security roles in United States; TypeScript appears in 7% of 86 comparable staff security roles in United States.

Quick facts

Is the Staff Security Engineer role remote?
It's hybrid — Ambience Healthcare expects some on-site time in San Francisco.
What's the salary range?
Ambience Healthcare lists $226,000–$283,000 for this role.
How much experience is required?
At least 8 years of relevant experience for this Staff Security Engineer role.
Where is the role based?
Ambience Healthcare is hiring for this position in San Francisco.
What's the tech stack?
Joblaze extracted these technologies from the posting: AWS, Go, Java, Python, TypeScript.
What seniority level is this role?
Ambience Healthcare targets staff-level candidates for this position.
Is this full-time or contract?
Full-time for this Staff Security Engineer role at Ambience Healthcare.

From the original posting

The Role:

Ambience runs real-time clinical workflows inside some of the country’s most security-sensitive health systems. Security can’t be bolted on—it must be engineered into the product.

This is a senior technical role focused on how Ambience designs, builds, and operates secure products. You’ll bring deep product security expertise and a strong software engineering foundation while extending your impact into cloud security as our AWS environment evolves.

You’ll partner with engineering from design through verification on high-risk changes and foundational product capabilities. You’ll own security analysis, technical requirements, risk decisions, and tooling—and contribute code wherever it creates the most leverage.

You’ll design secure systems, work fluently with code, and use AI to build context quickly, accelerate learning, and extend your reach—while grounding every decision in strong computer science, security fundamentals, and technical judgment.

What You’ll Own:

Secure design for high-risk changes — Guide initiatives from design proposals and architecture decisions through implementation and verification. Define threat models and security requirements, review sensitive implementation paths, and contribute prototypes, automation, or PRs when needed.

A credible, risk-based security backlog — Own findings from product reviews, bug bounty, penetration tests, audits, cloud tooling, and hands-on testing. Validate impact, recommend practical mitigations, and drive material issues to verified resolution or explicit risk acceptance.

Security engineering that scales — Expand coverage through guidance, developer enablement, automation, and well-operated tooling. Own tools across integration, tuning, triage, maintenance, and measurement—and improve or retire those that aren’t reducing risk.

Cloud risk reduction through our AWS migration — Partner with Platform and Infrastructure Engineering to reduce risk across IAM, network segmentation, workload isolation, secrets, logging, and configuration. Apply strong security fundamentals while building deeper AWS expertise, operationalizing our CNAPP, and establishing practical guardrails.

Security across the environment — Reduce risk across production, development, software delivery, enterprise AI, and internal systems. Help scope and remediate incidents, then turn lessons learned into durable improvements and secure paved paths.

Who You Are:

Staff-level product security judgment. You have the depth to operate independently across complex product security challenges—typically developed through 8+ years of experience—and the range to extend into adjacent areas such as cloud security. You don’t just find vulnerabilities; you design systems that prevent entire classes of them.

Engineering roots. You’ve shipped production code, built meaningful software or automation recently, and are strong in at least one backend or automation language such as Go, Python, Java, or TypeScript. You see security as an engineering problem, not a compliance checklist.

Product security depth. You understand authentication and authorization—including OAuth, OIDC, SAML, JWT, RBAC, and ReBAC—as well as API security, threat modeling, secure code review, vulnerability testing, and multi-tenant SaaS handling sensitive data. You can move from an architecture diagram into the implementation path that matters.

Cloud security fluency or aptitude. You have working knowledge of cloud security concepts such as IAM, network architecture, workload isolation, secrets, and logging—or a demonstrated ability to develop that expertise quickly.

Offensive validation instincts. You can reproduce vulnerabilities, conduct targeted dynamic testing, build proof-of-concept exploits, and distinguish exploitable risk from theoretical concern.

Demonstrated influence. You’ve helped engineering teams understand, prioritize, remediate, and verify material security risks.

Tooling ownership. You’ve owned security tooling or automation beyond deployment, including integration, tuning, triage, maintenance, and evaluation.

AI-augmented security engineering. You use AI as a force multiplier to develop depth in unfamiliar domains, expand your coverage, and move with greater speed. You validate its output against first principles and remain accountable for every technical and security decision.

Based in the Bay Area and able to work from our San Francisco office three days per week.

Nice to Have

  • Experience securing healthcare systems, PHI, or similarly regulated data

  • Experience designing or securing relationship-based or fine-grained authorization systems

  • Offensive security or red-team depth used to demonstrate impact and influence priorities

  • Experience securing enterprise AI applications, AI-enabled products, or internal AI adoption

  • Deep AWS security experience, including IAM, network architecture, workload isolation, configuration management, and CNAPP operations

Why Ambience

At most companies, security is reactive. At Ambience, it’s a product enabler. The systems you build will help us earn—and keep—the trust of the country’s largest health systems.

You’ll have meaningful ownership, direct access to leadership, and the opportunity to define product security at a company where it truly matters. You’ll join a small, high-trust team working on technically deep, mission-critical problems.

Pay Transparency

Every offer at Ambience includes both base salary and an equity grant. The base salary range for this role is:

  • (SF Bay Area): approximately $226k — $283k per year

This intentionally broad range provides flexibility for candidates to tailor their cash and equity mix based on individual preferences. Our compensation philosophy prioritizes meaningful equity grants, enabling team members to share directly in the impact they help create.

Are you outside of the range? We encourage you to still apply: we take an individualized approach to ensure that compensation accounts for all of the life factors that matter for each candidate.

  • Work on mission-critical AI technology that directly improves clinicians’ day-to-day lives and health system financial health across some of the most complex, high-stakes workflows in the world.

  • Comprehensive medical, dental, and vision coverage for you and your dependents

  • Parental leave to support your family needs

Standard company text repeated across Ambience Healthcare's postings is omitted here.

Similar positions

Ambience Healthcare
Staff Software Engineer, Distributed Systems
Ambience Healthcare · San Francisco
Ambience Healthcare
Staff Software Engineer, Product
Ambience Healthcare · San Francisco
Ambience Healthcare
Staff ML Engineer, Frontier AI
Ambience Healthcare · San Francisco
Ambience Healthcare
Clinical AI Researcher
Ambience Healthcare · San Francisco
Ambience Healthcare
Senior Machine Learning Engineer
Ambience Healthcare · San Francisco