The Role:Health systems trust Ambience with some of the most sensitive data there is, and proving that we deserve that trust is essential to every partnership we build. We are looking for a Senior GRC Analyst to own our governance, risk, and compliance program end to end, from SOC 2 and PHI governance to vendor and AI-model risk to the security evidence our customers rely on.
This is a senior individual contributor role with a broad mandate and real latitude to shape how the program runs. We treat GRC as an agile, evolving practice rather than a checkbox exercise. That means doing the technical digging yourself: using AI coding tools like Claude Code to answer compliance questions directly from the codebase instead of routing every question through engineering.
What You'll Own:- Own the compliance program: Run SOC 2 end to end, including the auditor relationship, evidence collection and interpretation in Vanta, and continuous audit readiness as our infrastructure evolves. Help lay the groundwork for AI governance frameworks like ISO 42001.
- Bring rigor to PHI governance: Build and maintain an authoritative inventory of where PHI lives and which systems and models touch it, and surface and close HIPAA and governance gaps.
- Investigate controls first-hand: Use AI coding assistants analytically to verify whether a control (for example, encryption at rest) is actually implemented, producing clear, evidenced answers without engineering hand-holding.
- Stand up vendor and AI-model risk reviews: Build and run the security review process for new vendors and AI model providers, partnering with legal and finance to bring every vendor into the fold with a documented risk assessment.
- Drive risk to closure: Partner with engineering to enumerate, prioritize, and remediate security risks on a predictable, auditable cadence, and author the security and compliance policies that engineering, legal, and GTM teams can actually follow.
- Be the front door for customer trust: Serve as first point of contact for RFPs and security questionnaires, and maintain a trust portal with current, customer-facing evidence.
Who You Are:- Hands-on SOC 2 ownership: Senior-level GRC or compliance experience in a SaaS environment, including owning a SOC 2 (or equivalent) audit from evidence collection through auditor sign-off, ideally using a GRC automation platform like Vanta or Drata.
- Technical curiosity: Comfortable using an AI coding tool like Claude Code to answer compliance questions directly from source code (you won't need to write code yourself), and able to threat-model a new vendor: what data it touches, where that data flows, and what controls it needs.
- Clear writing and communication: You write policies and standards that hold up to audit and that engineers can actually use, and you work directly and confidently with engineering, legal, and customers.
- Startup ownership mindset: You thrive in ambiguity, take a partially built function and make it accountable without waiting for structure to be handed to you, and happily work outside a narrow swim lane.
Nice-to-Have - Broader framework experience: ISO 27001 experience, and exposure to ISO 42001 or other AI governance frameworks.
- Regulated-industry background: Experience in healthcare, fintech, or another highly regulated industry.
Life at Ambience Working at Ambience means opting into a high-ownership, high-trust environment built for people who want to grow fast, operate decisively and focus on work that matters. This could be the right place for you if you want to
- Work on mission-critical AI technology that directly improves clinicians' day-to-day lives and health system financial health across some of the most complex, high-stakes workflows in the world.
- Join a "dream team" culture where we hire exceptional people, expect exceptional outcomes and invest deeply in feedback and continuous growth. We operate as a championship team, and that means being ok with hard, uncomfortable, ambiguous problems that lead to real greatness.
- Operate with real ownership and accountability in an environment where there are no bystanders: If something is broken, we fix it! You will have meaningful autonomy and be expected to drive work to completion.
To help you do your best work, we pair these expectations with benefits intentionally designed to help you feel supported and safe at Ambience and beyond. Some of our key benefits include
- Comprehensive medical, dental, and vision coverage for you and your dependents
- 401(k) with a company match of up to 3% of base salary
- A remote-friendly culture (with a San Francisco HQ) and full equipment provisioning to ensure you can work effectively from wherever you're based.
- Parental leave to support your family needs
- Annual company-wide off-sites, team off-sites and regular team lunches and all-hands gatherings, with travel, lodging and meals covered
- Flexible time off with no annual cap, company-wide holidays and an annual holiday shutdown from December 24-January 1 designed to support real rest and long-term sustainability.