Head of IT & Security
What security roles in crypto pay
64 salaries · our own dataMost security roles in crypto pay between $145k and $268k, with a median of $202k.
As Head of IT & Security at OpenZeppelin, you own the strategy, design, and continuous maturation of our Information Security Program, and lead the team executing it. You will manage security and privacy risks across a company whose open-source libraries secure over $35 trillion in onchain value, working with top enterprises, regulated institutions, and auditors. The next chapter is turning our established audit-ready program into an enterprise-grade security function that stands up to the most demanding customers, partners, and regulators, while safely accelerating our adoption of AI.
What you'll do
- Oversee identity and access management, provisioning, onboarding and offboarding, end-user security (MDM, endpoint protection, security training), physical security, disaster recovery, business continuity, and data backup, using automation and AI-powered workflows to scale IT and security operations faster than headcount.
- Set the strategic direction, multi-year roadmap, and risk posture of the Information Security Program; deliver on department OKRs; and own the IT and technology budget with ultimate responsibility for technology procurement.
- Own the secure adoption of AI across the company: evolve our AI governance framework, review and approve AI tools and agentic workflows, and secure our agentic infrastructure (identity, least-privilege tool and data access, secrets handling, monitoring, auditability). Manage frontier model providers as critical vendors, covering security and data-handling diligence, retention and training-use commitments, data processing agreements, and subprocessor flow-downs. Meet emerging obligations such as the EU AI Act, so we can make transparent, defensible commitments to enterprise customers.
- Own our audit, certification, and attestation strategy and execution (penetration testing, SOC 2 Type 2, ISO/IEC 27001, successor frameworks) alongside internal security audits. Run a third-party and vendor risk management program and serve as the external face of our security program with customer security teams, regulated financial institutions, and auditors.
- Maintain a comprehensive data map of how data flows into, through, and out of the organization, including flows to model providers and through agentic workflows, with data classification, records of processing, and a vendor/subprocessor inventory. Own privacy compliance in partnership with Legal: GDPR, CCPA/CPRA, data processing agreements and contractual security commitments, and privacy-by-design reviews of new products and features.
- Own the incident response program end-to-end, including playbooks, tabletop exercises, post-incident reviews, and breach-notification obligations in partnership with Legal. Manage our bug bounty programs and partner with development teams to embed security best practices in the software development lifecycle and our software offerings.
What you bring
- 10+ years of Security and IT experience, including 3+ years leading an IT Security and GRC function (not solely IT operations) in a high-growth tech company, with demonstrated ownership of strategy, not just execution.
- A demonstrated trajectory toward CISO: you have owned a security program end-to-end, presented to executives or boards, and can articulate the "why" behind every control you have implemented.
- Experience securing or governing AI/LLM-enabled products or enterprise AI adoption, including agentic systems and third-party model-provider risk, with an ability to apply privacy and data-protection laws and practices (e.g., GDPR, CCPA/CPRA) in the AI context.
Nice to have
- 5+ years working in blockchain or FinTech with an enterprise client base (e.g., financial services), including navigating rigorous third-party security diligence.
What we offer
- Fully remote work with company gatherings around the world
- Flexible time off
- 8 weeks of paid leave for primary caregivers, 4 weeks for secondary caregivers, and a one-time $3,600 baby bonus
- Up to $500 in home office equipment support
- Medical insurance
- Learning and development opportunities
- Monthly stipend for your preferred co-working space
About OpenZeppelin
OpenZeppelin is the security standard onchain finance is built on. Founded in 2015, our mission is to accelerate the world's transition to an open financial system, built on open standards and secured by rigorous research. Our open-source Contract Libraries have facilitated over $35 trillion in onchain value and are used by 10 of the top 10 tokenized money market funds and 9 of the top 10 stablecoins by market cap. We combine AI-native security tooling with deep research and a decade of audit expertise to support leading institutions across the full secure development lifecycle.
