435,444open jobs
15,239companies
62,530added this week
Browse all
Salary
$170k – $318k per year (Estimated)
Location
Remote (Argentina)
Seniority
Architect · 10+ years exp
Overview
Company
Impact
Profile match
OpenZeppelin is a smart contract security company founded in 2015 with origins in Buenos Aires. Its open-source contract libraries are the de facto standard for token and access control implementations across Ethereum and compatible chains. The firm also performs audits and sells Defender, a platform for secure contract operations, upgrades and incident response.

About us

OpenZeppelin is the security standard onchain finance is built on. Founded in 2015, our mission is to accelerate the world's transition to an open financial system, built on open standards and secured by rigorous research.

Our open-source Contract Libraries have facilitated over $35 trillion in onchain value and are used by 10 of the top 10 tokenized money market funds and 9 of the top 10 stablecoins by market cap.

We combine AI-native security tooling with deep research and a decade of audit expertise to support leading institutions and crypto-native teams shaping the next generation of digital assets like DTCC, Fidelity, Coinbase, Uniswap, Aave, the Ethereum Foundation, and many more across the full secure development lifecycle.

Please note: Always refer to OpenZeppelin's official job page for the most accurate information about our open roles, as we have seen multiple third party job sites posting inaccurate information.

The Information Security Team 

The Information Security function operates independently under our Legal team and owns everything that keeps the OpenZeppelin organization secure. That means managing our Security, Privacy & IT Program end-to-end: our SOC 2 and ISO 27001 posture, vendor and privacy risk, incident response, our bug bounty programs, and the identity, endpoint, and access systems the whole company depends on. It is also the team our customers meet during security diligence. As our enterprise relationships deepen, increasingly with banks and other regulated institutions, our own program must be as credible as the security we deliver to customers.

Today that program is established and audit-ready. The next chapter is turning it into an enterprise-grade security function that stands up to the scrutiny of the most demanding enterprise customers, partners, and regulators, while safely accelerating our adoption of AI across the company.

What you'll be doing

You will own the strategy, design, and continuous maturation of OpenZeppelin's Information Security Program, and be accountable for managing the team executing it. You can issue-spot security and privacy risks before they materialize, explain the principles behind security and compliance controls to auditors and enterprise security teams, and calibrate our security program proportionate to risk. 

  • Strategy, governance and budget: Set the strategic direction, multi-year roadmap, and risk posture of the Information Security Program; deliver on department OKRs; and own the IT and technology budget, with ultimate responsibility for technology procurement.
  • AI security and governance: Own the secure adoption of AI across the company: evolve our AI governance framework, review and approve AI tools and agentic workflows, and secure our agentic infrastructure (identity, least-privilege tool and data access, secrets handling, monitoring, auditability). Manage frontier model providers as critical vendors, covering security and data-handling diligence, retention and training-use commitments, DPAs and subprocessor flow-downs. Meet emerging obligations such as the EU AI Act, so we can make transparent, defensible commitments to enterprise customers about how our products and internal AI usage handle their data.
  • Compliance, audit and enterprise trust: Own our audit, certification, and attestation strategy and execution (penetration testing, SOC 2 Type 2, ISO/IEC 27001, successor frameworks) alongside internal security audits; run a third-party and vendor risk management program; and serve as the external face of our security program with customer security teams, regulated financial institutions, and auditors.
  • Privacy and data governance: Maintain a comprehensive data map of how data flows into, through, and out of the organization, including flows to model providers and through agentic workflows, with data classification, records of processing, and a vendor/subprocessor inventory. Own privacy compliance in partnership with Legal: GDPR, CCPA/CPRA, DPAs and contractual security commitments, and privacy-by-design reviews of new products and features.
  • Security operations and incident response: Own the incident response program end-to-end, including playbooks, tabletop exercises, post-incident reviews, and breach-notification obligations in partnership with Legal. Manage our bug bounty programs, and partner with development teams to embed security best practices in the SDLC and our software offerings.
  • IT and infrastructure: Oversee identity and access management, provisioning and onboarding/offboarding, end-user security (MDM, endpoint protection, security training), physical security, disaster recovery, business continuity, and data backup, using automation and AI-powered workflows to make IT and security operations scale faster than headcount.

You have

  • 10+ years of Security and IT experience, including 3+ years leading a IT Security and GRC function (not solely IT operations) in a high-growth tech company, with demonstrated ownership of strategy, not just execution.
  • A demonstrated trajectory toward CISO: you have owned a security program end-to-end, presented to executives or boards, and can articulate the "why" behind every control you have implemented.
  • Experience securing or governing AI/LLM-enabled products or enterprise AI adoption including agentic systems and third-party model-provider risk, with an ability to apply privacy and data-protection laws and practices (e.g., GDPR, CCPA/CPRA) in the AI context.

Nice to have

  • 5+ years working in blockchain or a FinTech with an enterprise client base (e.g., financial services), including navigating rigorous third-party security diligence.

Logistics:

Our interview process takes place on Google Meet or Zoom and tends to consist of the following stages:

  • Recruiter Call (30 minutes)
  • Hiring Manager Call (30 minutes)
  • Team Interview (30 minutes)
  • Leadership Interview (30 minutes)
  • Paid work test (up to 20 hours of paid work)
  • Reference checks

Benefits

  • Meet your teammates at company gatherings around the world
  • Enjoy the flexibility of fully remote work
  • Take the time you need with flexible time off
  • Grow your family with 8 weeks of paid leave for primary caregivers, 4 weeks for secondary caregivers, and a one-time $3,600 baby bonus
  • Build your ideal home office with up to $500 in equipment support
  • Stay covered with medical insurance
  • Keep growing with learning and development opportunities
  • Get a monthly stipend for your preferred co-working space

At OpenZeppelin, we are an equal opportunity employer and we value different perspectives. We are committed to building a diverse workforce. This includes but is not limited to gender, race, sexual orientation, religion, national origin and other characteristics that make each one of us unique. In this uniqueness, we find the most value. Come join us!

Use of AI as part of the recruiting process

As part of OpenZeppelin’s recruitment process, we may use automated tools, including artificial intelligence, to assist in reviewing applications and assessing candidate qualifications. These tools are used to support our People team by identifying relevant skills and experience, and are not used to make decisions solely by automated means. All hiring decisions involve human review. Any personal data provided as part of your application will be processed in accordance with OpenZeppelin’s Data Privacy Notice.

If you have questions about this recruitment process or would like to request human review of your application, please contact us at [email protected].

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
435,444 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
Remote/Hybrid • Full-Time • PhD • Dublin
AI/ML
AI Agents
Agentforce
Management
Slack
Marketing
Salesforce
Apply
AI Engineering Manager 10 hours ago
In office • 8+ years exp • Bengaluru
AI/ML
AI Agents
DevOps
GCP
CI/CD
AWS
Kubernetes
Platform Engineering
Incident Management
Apply
AI QA Engineer 10 hours ago
Remote/Hybrid • 6+ years exp
Python
JavaScript
TypeScript
AI/ML
LangChain
Claude
ChatGPT
LlamaIndex
Prompt Engineering
AI Agents
Llama
Gemini
LLM
RAG
OpenAI
Agentic Workflows
DevOps
GitHub Actions
Azure
CI/CD
Jenkins
Docker
Kubernetes
Self-Healing
GitHub
QA
Selenium
Cypress
Playwright
Appium
Apply
Software Engineer MTS 10 hours ago
$88k – $198k per year (Estimated) • In office • Full-Time • PhD • Dublin
Python
PowerShell
Apex
Apex
MuleSoft
AI/ML
AI Agents
Agentforce
Agentic Workflows
DevOps
CI/CD
AWS
AWS Fargate
AWS Lambda
API Gateway
Cybersecurity
osquery
Management
Slack
Apply
$63k – $130k per year (Estimated) • In office • 8+ years exp • Bachelor's Degree • Hong Kong
AI/ML
AI Agents
Web3
Smart Contracts
DeFi
Staking
Apply
$122k – $266k per year (Estimated) • Remote • 3+ years exp
Rust
Move
Cairo
Solidity
Cairo
OpenZeppelin Cairo
AI/ML
Cursor
Claude
Claude Code
Model Context Protocol
Anthropic SDK
Anthropic
Web3
Stellar
Anchor
Solana
Arbitrum
Aptos
Aave
OpenZeppelin
Starknet
Uniswap
Smart Contracts
Ethereum
DeFi
Token Standards
Apply
Remote • 3+ years exp
Move
Cairo
Solidity
Cairo
OpenZeppelin Cairo
AI/ML
Cursor
Claude
Claude Code
Model Context Protocol
Anthropic SDK
Tokenization
Anthropic
Web3
Stellar
Arbitrum
Aptos
Cardano
Chainlink
Aave
OpenZeppelin
Starknet
Uniswap
Smart Contracts
Ethereum
DeFi
Tokenomics
Aleo
LayerZero
Wormhole
Axelar
Chainlink CCIP
Apply
$112k – $256k per year (Estimated) • Remote • 6+ years exp
Solidity
AI/ML
Tokenization
Web3
Stellar
Aave
OpenZeppelin
Uniswap
Smart Contracts
Ethereum
Nansen
Apply
See all jobs
This is one of many
435,444 more open roles from verified company boards, updated every day.