--- title: 'Head of IT & Security at OpenZeppelin' canonical: 'https://feeny.ai/job/head-of-it-security-openzeppelin-remote-dvmhaxb57y1g' type: 'job' last_seen: '2026-09-15' --- # Head of IT & Security at OpenZeppelin - **Company:** OpenZeppelin - **Location:** Remote - **Work type:** remote - **Posted:** 2026-09-09 - **Last confirmed live:** 2026-09-15 - **Apply:** https://openzeppelin.com/careers/opening/?gh_jid=7985565003 ## Job description ## About us OpenZeppelin is the security standard onchain finance is built on. Founded in 2015, our mission is to accelerate the world's transition to an open financial system, built on open standards and secured by rigorous research. Our open-source Contract Libraries have facilitated over $35 trillion in onchain value and are used by 10 of the top 10 tokenized money market funds and 9 of the top 10 stablecoins by market cap. We combine AI-native security tooling with deep research and a decade of audit expertise to support leading institutions and crypto-native teams shaping the next generation of digital assets like DTCC, Fidelity, Coinbase, Uniswap, Aave, the Ethereum Foundation, and many more across the full secure development lifecycle. Please note: Always refer to OpenZeppelin's official job page for the most accurate information about our open roles, as we have seen multiple third party job sites posting inaccurate information. The IT & Security Team The Information Security function operates independently under our Legal team and owns everything that keeps the OpenZeppelin organization secure. That means managing our Security, Privacy & IT Program end-to-end: our SOC 2 and ISO 27001 posture, vendor and privacy risk, incident response, our bug bounty programs, and the identity, endpoint, and access systems the whole company depends on. It is also the team our customers meet during security diligence. As our enterprise relationships deepen, increasingly with banks and other regulated institutions, our own program must be as credible as the security we deliver to customers. Today that program is established and audit-ready. The next chapter is turning it into an enterprise-grade security function that stands up to the scrutiny of the most demanding enterprise customers, partners, and regulators, while safely accelerating our adoption of AI across the company. ## What you'll be doing You will own the strategy, design, and continuous maturation of OpenZeppelin's Information Security Program, and be accountable for managing the team executing it. You can issue-spot security and privacy risks before they materialize, explain the principles behind security and compliance controls to auditors and enterprise security teams, and calibrate our security program proportionate to risk. - IT and infrastructure: Oversee identity and access management, provisioning and onboarding/offboarding, end-user security (MDM, endpoint protection, security training), physical security, disaster recovery, business continuity, and data backup, using automation and AI-powered workflows to make IT and security operations scale faster than headcount. - Strategy, governance and budget: Set the strategic direction, multi-year roadmap, and risk posture of the Information Security Program; deliver on department OKRs; and own the IT and technology budget, with ultimate responsibility for technology procurement. - AI security and governance: Own the secure adoption of AI across the company: evolve our AI governance framework, review and approve AI tools and agentic workflows, and secure our agentic infrastructure (identity, least-privilege tool and data access, secrets handling, monitoring, auditability). Manage frontier model providers as critical vendors, covering security and data-handling diligence, retention and training-use commitments, DPAs and subprocessor flow-downs. Meet emerging obligations such as the EU AI Act, so we can make transparent, defensible commitments to enterprise customers about how our products and internal AI usage handle their data. - Compliance, audit and enterprise trust: Own our audit, certification, and attestation strategy and execution (penetration testing, SOC 2 Type 2, ISO/IEC 27001, successor frameworks) alongside internal security audits; run a third-party and vendor risk management program; and serve as the external face of our security program with customer security teams, regulated financial institutions, and auditors. - Privacy and data governance: Maintain a comprehensive data map of how data flows into, through, and out of the organization, including flows to model providers and through agentic workflows, with data classification, records of processing, and a vendor/subprocessor inventory. Own privacy compliance in partnership with Legal: GDPR, CCPA/CPRA, DPAs and contractual security commitments, and privacy-by-design reviews of new products and features. - Security operations and incident response: Own the incident response program end-to-end, including playbooks, tabletop exercises, post-incident reviews, and breach-notification obligations in partnership with Legal. Manage our bug bounty programs, and partner with development teams to embed security best practices in the SDLC and our software offerings. You have - 10+ years of Security and IT experience, including 3+ years leading a IT Security and GRC function (not solely IT operations) in a high-growth tech company, with demonstrated ownership of strategy, not just execution. - A demonstrated trajectory toward CISO: you have owned a security program end-to-end, presented to executives or boards, and can articulate the "why" behind every control you have implemented. - Experience securing or governing AI/LLM-enabled products or enterprise AI adoption including agentic systems and third-party model-provider risk, with an ability to apply privacy and data-protection laws and practices (e.g., GDPR, CCPA/CPRA) in the AI context. ## Nice to have - 5+ years working in blockchain or a FinTech with an enterprise client base (e.g., financial services), including navigating rigorous third-party security diligence. Logistics: Our interview process takes place on Google Meet or Zoom and tends to consist of the following stages: - Recruiter Call (30 minutes) - Hiring Manager Call (30 minutes) - Team Interview (30 minutes) - Leadership Interview (30 minutes) - Paid work test (up to 20 hours of paid work) - Reference checks ## Benefits - Meet your teammates at company gatherings around the world 😎 - Enjoy the flexibility of fully remote work 🌎 - Take the time you need with flexible time off 🏝 - Grow your family with 8 weeks of paid leave for primary caregivers, 4 weeks for secondary caregivers, and a one-time $3,600 baby bonus 💙 - Build your ideal home office with up to $500 in equipment support 🪑 - Stay covered with medical insurance 🏥 - Keep growing with learning and development opportunities 🧠 - Get a monthly stipend for your preferred co-working space 💻 At OpenZeppelin, we are an equal opportunity employer and we value different perspectives. We are committed to building a diverse workforce. This includes but is not limited to gender, race, sexual orientation, religion, national origin and other characteristics that make each one of us unique. In this uniqueness, we find the most value. Come join us! Use of AI as part of the recruiting process As part of OpenZeppelin’s recruitment process, we may use automated tools, including artificial intelligence, to assist in reviewing applications and assessing candidate qualifications. These tools are used to support our People team by identifying relevant skills and experience, and are not used to make decisions solely by automated means. All hiring decisions involve human review. Any personal data provided as part of your application will be processed in accordance with OpenZeppelin’s [Data Privacy Notice](https://www.openzeppelin.com/privacy). If you have questions about this recruitment process or would like to request human review of your application, please contact us at talent@openzeppelin.com. ## About OpenZeppelin ## Company Overview - **One-liner**: OpenZeppelin provides the security standard for onchain finance, offering smart contract libraries, security audits, and a developer security platform to help organizations build, secure, and operate blockchain applications. - **Entity Type**: Private (Venture-backed; last known funding round in 2023) - **Headquarters**: United States (distributed/remote-first company with team members across 33+ countries) - **Founded**: 2015 - **Founders**: Demian Brener ## Core Business - Primary industry/industries: Blockchain Security, Smart Contract Development, Cybersecurity, Financial Infrastructure - Target customers: B2B — DeFi protocols, blockchain platforms, financial institutions, and crypto-native organizations (e.g., Coinbase, Ethereum Foundation, Compound, Aave, Uniswap, Matter Labs, ANZ Bank) - Mission or purpose statement: "To accelerate the world’s transition to an open financial system." ## Products & Services - **[OpenZeppelin Contracts](https://www.openzeppelin.com/contracts)**: The industry-standard, battle-tested open-source library for secure smart contract development in Solidity and Cairo. Used by 9 of the top 10 stablecoins and 10 of the top 10 tokenized funds. Over $33.2 trillion in total value has been transferred via these contracts. - **[OpenZeppelin Defender](https://www.openzeppelin.com/defender)**: A developer security platform for operating onchain applications. Includes a Relayer for secure transaction management, Monitors for threat detection and alerting, and Actions for automated incident response. - **[Security Audits](https://www.openzeppelin.com/security-audits)**: Gold-standard smart contract, ZKP, and infrastructure audits. The team has uncovered 700+ critical and high vulnerabilities, with over 1 million lines of code reviewed. They pioneered the smart contract security audit practice. - **[Ethernaut CTF](https://ethernaut.openzeppelin.com/)**: The #1 educational resource for smart contract security, with +140K plays across 5 networks and 10 languages. - **Security Research & Standards**: Active contributors to Ethereum Improvement Proposals (EIPs) and ERCs, including Account Abstraction (ERC-1271), Metatransactions (ERC-2771), and Upgradeability (ERC-7201, ERC-1967). Members of EthTrust and SEAL911. ## Market Standing - **Valuation/Market Cap**: Not publicly disclosed - **Key Metric**: Total Value Locked (TVL) secured: over **$250 billion** across client protocols. Total value transferred via OpenZeppelin Contracts: over **$33.2 trillion**. - **Notable Investors/Partners**: Raised a Venture Round in March 2023 with 1 investor (specific lead not publicly named in available data). Clients include Coinbase, Ethereum Foundation, Compound, Aave, Uniswap, Matter Labs, and ANZ Bank. - **Growth Signals**: 95%+ customer re-engagement rate; 71 NPS score; 200+ active customers; 140+ global team members; operates in 33+ countries; 64% of all active wallets have interacted with OpenZeppelin Contracts. ## Competitive Advantages - **Market Dominance & Trust**: OpenZeppelin Contracts are the de facto standard for secure smart contract development, used by the vast majority of top DeFi protocols and tokenized funds. - **Pioneering Expertise**: As the company that pioneered the smart contract security audit practice, they have a decade of experience and unmatched depth in blockchain security research. - **Full Lifecycle Coverage**: The only company that offers an integrated stack from open-source development libraries (Contracts) to operational security (Defender) to expert auditing, covering the entire development lifecycle. - **Neutral & Research-Driven**: A neutral, strategic partner committed to customer success, with a strong research culture that contributes directly back to the ecosystem (EIPs, ERCs, educational tools like Ethernaut). - **AI-First Security**: Recently introduced AI-powered security audits alongside the release of Contracts 5.0, positioning them at the cutting edge of automated vulnerability detection. ## Strategic Focus - **AI-Native Security**: Integrating AI into security audits and the Defender platform to provide continuous, automated security across the full lifecycle, enabling capital markets to deploy and operate at scale in regulatory alignment. - **Expanding into Privacy & Confidentiality**: Entering the privacy and confidentiality space (Zero-Knowledge Proof audits and infrastructure). - **Institutional Onboarding**: Deepening partnerships with traditional financial institutions undergoing onchain transformation, helping them meet regulatory and security requirements. - **Community & Education**: Continuing to grow the Ethernaut CTF and contribute to open standards to foster a more secure ecosystem. ## Why Work Here - **Mission-Driven**: Join a team dedicated to "accelerating the world's transition to an open financial system" — a high-impact, transformative goal. - **Remote-First & Global**: Fully remote company with team members in 40+ countries. They foster connection through regular in-person gatherings in different locations worldwide. - **World-Class Team**: Work alongside globally distributed engineers, researchers, and security experts who are defining the foundations for the next generation of financial services. Alumni have gone on to top roles at companies like Chainalysis, Coinbase, Matter Labs, and Trail of Bits. - **Strong Values**: The culture is built on Intellectual Curiosity, Commitment to Excellence, Ability to Ship, Customer Centricity, Team Spirit, and a Strong Sense of Purpose. - **Benefits**: Fully remote work, flexible time off, paid parental leave for primary or secondary caregiver, one-time home office stipend of up to $500 USD, medical coverage, annual Learning & Development budget, and referral incentives. - **Hiring Process**: A transparent, 6-step process designed to be fair and thorough, including a paid work trial that emulates real work. Typically completed in up to 6 weeks. - **Growth & Impact**: With 200+ active customers and $250B+ in TVL secured, your work directly protects billions of dollars in digital assets. ## Sources 1. [openzeppelin.com](https://www.openzeppelin.com/) 2. [openzeppelin.com/about-us](https://www.openzeppelin.com/about-us) 3. [openzeppelin.com/careers](https://www.openzeppelin.com/careers) 4. [linkedin.com/company/openzeppelin](https://www.linkedin.com/company/openzeppelin) ## Other roles at OpenZeppelin - [Program Manager (Customer Success)](https://feeny.ai/job/program-manager-customer-success-openzeppelin-remote-zxpm1gz29mzk) - [Principal Security Engineer (Solana)](https://feeny.ai/job/principal-security-engineer-solana-openzeppelin-remote-x1g8qg8msj4g) - [Technical Sales Lead, Ecosystems](https://feeny.ai/job/technical-sales-lead-ecosystems-openzeppelin-remote-hs2maa1a17ma) - [Lead Blockchain Security Developer (Canton)](https://feeny.ai/job/lead-blockchain-security-developer-canton-openzeppelin-remote-y5m61rsmb7dp) - [Head of IT & Security](https://feeny.ai/job/head-of-it-security-cin7-auckland-65m9gvj3nkg8) — Auckland, New Zealand - [Head of IT & Security](https://feeny.ai/job/head-of-it-security-nexhealth-san-francisco-california-aysjvekgzp2d) — San Francisco California, United States / Seattle Washington, United States