GRC Analyst
Job Description
About Us: Here at Ambience, we never set out to be just another scribe. We’re building the AI intelligence platform that restores humanity to healthcare and drives meaningful ROI for health systems across the country. Our technology helps providers focus on delivering great care by removing the administrative burden that pulls them away from patients and away from their most impactful work. Ambience delivers real-time coding-aware documentation and clinical workflow support across ambulatory, emergency and inpatient settings at the top health systems in North America. Our teams operate relentlessly with extreme ownership to build the best solutions for our health system partners. We value candor, positivity and deep thought — and we expect a lot from each other because we know the problems we’re solving truly matter. Ambience was ranked #1 for Improving the Clinician Experience in the KLAS Research Emerging Solutions Top 20 Report, recognized by Fast Company as one of the Next Big Things in Tech, named one of the best AI companies in healthcare by Inc., and selected as a LinkedIn Top Startup in 2024 and 2025. We’re backed by Oak HC/FT, Andreessen Horowitz (a16z), OpenAI Startup Fund, and Kleiner Perkins — and we’re just getting started. The Role: Health systems trust Ambience with some of the most sensitive data there is, and proving that we deserve that trust is essential to every partnership we build. We are looking for a Senior GRC Analyst to own our governance, risk, and compliance program end to end, from SOC 2 and PHI governance to vendor and AI-model risk to the security evidence our customers rely on. This is a senior individual contributor role with a broad mandate and real latitude to shape how the program runs. We treat GRC as an agile, evolving practice rather than a checkbox exercise. That means doing the technical digging yourself: using AI coding tools like Claude Code to answer compliance questions directly from the codebase instead of routing every question through engineering. What You’ll Own: Own the compliance program: Run SOC 2 end to end, including the auditor relationship, evidence collection and interpretation in Vanta, and continuous audit readiness as our infrastructure evolves. Help lay the groundwork for AI governance frameworks like ISO 42001. Bring rigor to PHI governance: Build and maintain an authoritative inventory of where PHI lives and which systems and models touch it, and surface and close HIPAA and governance gaps. Investigate controls first-hand: Use AI coding assistants analytically to verify whether a control (for example, encryption at rest) is actually implemented, producing clear, evidenced answers without engineering hand-holding. Stand up vendor and AI-model risk reviews: Build and run the security review process for new vendors and AI model providers, partnering with legal and finance to bring every vendor into the fold with a documented risk assessment. Drive risk to closure: Partner with engineering to enumerate, prioritize, and remediate security risks on a predictable, auditable cadence, and author the security and compliance policies that engineering, legal, and GTM teams can actually follow. Be the front door for customer trust: Serve as first point of contact for RFPs and security questionnaires, and maintain a trust portal with current, customer-facing evidence. Who You Are: Hands-on SOC 2 ownership: Senior-level GRC or compliance experience in a SaaS environment, including owning a SOC 2 (or equivalent) audit from evidence collection through auditor sign-off, ideally using a GRC automation platform like Vanta or Drata. Technical curiosity: Comfortable using an AI coding tool like Claude Code to answer compliance questions directly from source code (you won’t need to write code yourself), and able to threat-model a new vendor: what data it touches, where that data flows, and what controls it needs. Clear writing and communication: You write policies and standards that hold