About the job
About Us:
At Ambience Healthcare, we are not just another documentation service; we are pioneering an AI-driven platform that reintroduces humanity into healthcare, creating substantial returns on investment for health systems nationwide.
Our innovative technology empowers healthcare providers to concentrate on exceptional patient care by alleviating the administrative burdens that detract from their crucial responsibilities. We provide real-time, coding-aware documentation and clinical workflow assistance across various healthcare settings, including ambulatory, emergency, and inpatient environments, collaborating with the leading health systems in North America.
We are committed to delivering the best solutions for our partners, operating with a strong sense of ownership and a culture that values transparency, positivity, and thoughtful discussion. Our team holds each other to high standards because we understand the significance of the challenges we tackle.
Recognized as a leader in enhancing clinician experiences by KLAS Research, featured by Fast Company as one of the Next Big Things in Tech, acknowledged by Inc. as one of the best AI companies in healthcare, and listed as a LinkedIn Top Startup for 2024 and 2025, Ambience is backed by prestigious investors including Oak HC/FT, Andreessen Horowitz (a16z), OpenAI Startup Fund, and Kleiner Perkins. Our journey is just beginning.
The Role:
As a key member of our team, you will spearhead the detection engineering and incident response program within a HIPAA-compliant, AI-driven environment, where the threat landscape includes LLM-powered agents operating across diverse infrastructures. Your responsibilities will include writing production code, architecting security data pipelines, and establishing high standards for detection and response within a rapidly evolving attack surface.
This position requires a hybrid work model based in our San Francisco office (3 days per week).
What You’ll Own:
Detection Engineering: Establish a detection pipeline covering our highest-risk surfaces, including AWS, Kubernetes, Okta, endpoints, and SaaS tools. Create environment-specific detections that ensure reliable alerting for the on-call team.
Incident Response: Develop a comprehensive incident response program, including playbooks, escalation processes, evidence collection, and post-mortems. Ensure all procedures are well-documented, practiced, and meet regulatory requirements.

