Responsibilities
- Deploy a detection system across high-risk environments including cloud infrastructure, container platforms, identity providers, endpoint devices, and third-party software services
- Develop and maintain detection rules tailored to the environment, ensuring reliable and actionable alerts trusted by incident responders
- Design and implement a complete incident response framework, including response procedures, escalation protocols, data preservation, and post-incident reviews
- Maintain documented and regularly tested processes that meet both operational efficiency and HIPAA compliance requirements
- Assess, implement, and integrate detection and response technologies such as SIEM, EDR, SOAR, and native cloud security tools
- Create custom automation and internal tools to minimize manual effort and accelerate response timelines
- Apply large language models where they provide measurable improvements in threat detection, analysis, or investigation workflows
- Identify and respond to security threats specific to clinical AI applications and autonomous agent behaviors, including unusual access patterns, misuse of credentials, data theft, and emerging attack techniques
Benefits
- Significant equity compensation included as part of total rewards
- Full health coverage including medical, dental, and vision insurance for employees and their families
- 401(k) retirement plan with company matching up to 3% of base salary
- Remote-first work environment with headquarters in San Francisco
- Complete hardware and equipment provided for all employees
- Paid parental leave policy
- Company-funded team gatherings, including annual off-sites, team events, regular lunches, and all-hands meetings, with travel and accommodations covered
- Unlimited flexible time off without a set annual limit
- Recognized public and company holidays observed annually
- Mandatory office closure from December 24 to January 1 each year
Work Arrangement
Hybrid
Team
Small team; this role is the first dedicated hire for detection and response
Other
- Emails originating from @ambiencehealthcare.com are authentic and authorized
- No legitimate communication will ever request app downloads or payment actions
- Suspicious messages should be reported to LinkedIn and the FBI


