Ambi
IT Operations & AI Agent Engineer
San Francisco, CA · $180,000-$220,000 · Full-time
About the company
Ambi is a stealth AI-hardware startup building an integrated system across hardware, software, and cloud that acts as a "living memory", capturing conversations, meetings, and the signals of everyday life so people move from intention to action without typing or UI navigation as the bottleneck. Core surfaces are Apple Watch, iPhone, and a Mac desktop app, with an agent. ASR (speech-to-text) pipeline underneath. It was founded by the ex-CEO's team out of Plaud (the AI note-taking hardware company that scaled ~$1M to $100M ARR in two years), a group that grew disenchanted with how Plaud was building and left to take a high-agency swing at next-gen hardware.
Ambi is ~40 people globally (majority in China), well-capitalized (~$20M raised), and is now building out its US core team in San Francisco.
About the role
This seat owns Ambi's US-China data-compliance boundary and builds the AI-agent layer so the China R&D team can operate safely without crossing it. Ambi's compliance model requires user data and related operations to stay in the US; the China team can't directly access sensitive data or production systems. You own day-to-day operations of the US production environment (data storage, key management, decryption services) and design and build an AI-agent platform that lets China R&D perform operational tasks (deployments, log lookups, monitoring queries) through conversational and tool-calling interfaces (function calling, MCP) instead of direct system access. It is a blend of DevOps/SRE, security/compliance, and applied AI-agent engineering, working closely with legal counsel and coordinating constantly with a China-based team across time zones and languages.
You implement agent-layer guardrails (data masking, scoped permissions, approval workflows) so the agent can perform tasks without exposing raw sensitive data. You maintain complete, auditable logs of all operations. You work with legal to implement US data-compliance requirements (for example CCPA) on the technical side. You manage access control, security monitoring, and incident response for US infrastructure. You own that boundary end to end, hold it, and build around it. Comfort with ambiguity and a fast-moving pre-launch environment is required. Cross-functional with legal, US ops, and China R&D.
Bar: DevOps/SRE or infrastructure engineering with cloud (AWS/GCP/Azure), Kubernetes, and CI/CD. You have built AI-agent systems with LLM tool-calling and agent frameworks (LangChain, MCP, and the like). Security and compliance background (encryption, key management, access control) is a strong plus. Similar cross-border data-compliance architectures (TikTok-style setups) and startup experience are nice to have. Hybrid, three days a week in the San Francisco office. Visa sponsorship is limited. Equity is about 0.05% to 0.2%. Health, dental, vision, 401(k) match, generous PTO, and global travel.
Apply
Fill this out and then pick a time to talk.
