
As Principal Security Engineer (Solana) at OpenZeppelin, you set the technical direction for OpenZeppelin's work on the SVM. You are not joining an existing Solana team; you define what OpenZeppelin's Solana practice looks like, in the open and under your own name. Your first focus is a confidential computing track on Solana, porting fully homomorphic encryption primitives to the SVM runtime, designing the confidential token standard and SDK patterns, and building developer abstractions. Beyond that, you are the SVM technical lead across the portfolio, shaping how OpenZeppelin scopes and staffs Solana audits and contributing to open-source libraries and tooling.
What you'll do
- Lead Solana workstreams end to end, from architecture and implementation through audit preparation, deployment and post-launch hardening, making the technical calls and bringing others with you.
- Build production-grade programs and libraries where security is the primary constraint, with most of your code reviewed by world-class auditors.
- Own hard design questions of a young ecosystem: storage and compute cost models, upgradability and governance, and idiomatic patterns for primitives with no Solana precedent.
- Run client-facing roadmap and design discussions independently as the technical voice in the room.
- Raise the level of everyone around you by reviewing the team's Solana work, setting standards, and shortening the ramp for incoming engineers.
- Represent OpenZeppelin in the ecosystem: engage with the Solana Foundation and core teams, publish the work, and contribute to open-source libraries and tooling.
- Use AI as a core daily tool to build agents, skills and workflows that compound the team's leverage and apply it to security work.
- Collaborate with blockchain security researchers on cross-team research and protocol-level threat analysis.
What you bring
- 3+ years building on Solana in production, with programs you shipped that other people depend on.
- Demonstrated ability to lead multi-quarter workstreams, make consequential technical calls, and carry them through review, disagreement and shipping.
- Deep SVM fluency: the account model, program-derived addresses, cross-program invocation, compute budgeting, rent and account lifecycle, versioned transactions and address lookup tables, and program upgradability with its governance implications.
- Productivity in Anchor and comfort working directly against the runtime when needed, understanding the cost of each choice.
- A security-first mindset: you think adversarially about every line of code you write and have demonstrable experience auditing, breaking or hardening production systems.
- An AI-native workflow using Claude Code, Cursor or equivalent as your daily driver, with measurable productivity gains, clear opinions on tool use, and at least one shipped non-trivial AI-powered tool, agent or automation pipeline in production.
- Fluency in client-facing communication (English), running roadmap calls, defending design decisions and translating technical depth for non-technical stakeholders.
- Alignment with OpenZeppelin's values: intellectual curiosity, strong sense of purpose, attention to detail, and ability to thrive in a fully distributed team.
Nice to have
- Contributions to standards such as Solana Improvement Documents, SPL and Token 2022 extensions, or the Wallet Standard.
- Public standing in the Solana ecosystem through widely used programs or tooling, published research, or conference talks.
- Cryptography background in fully homomorphic encryption, zero-knowledge systems, or applied cryptography.
- Compute unit and cost optimization depth, such as low-overhead runtimes or a track record of making expensive programs cheap.
- Prior audit or security research output including published reports, CTF participation, responsible disclosures, or security tooling.
- Experience applying AI to security work such as audit assistance, vulnerability research, fuzzing, or invariant analysis.
- Hands-on experience with other non-EVM ecosystems: Move-based chains, Stellar and Soroban, Arbitrum Stylus, or Starknet.
- Experience working alongside a foundation or core protocol team where the deliverable is a standard others adopt.
What we offer
- Company gatherings around the world to meet your teammates
- Fully remote work
- Flexible time off
- 8 weeks of paid leave for primary caregivers, 4 weeks for secondary caregivers, and a one-time $3,600 baby bonus
- Up to $500 in home office equipment support
- Medical insurance
- Learning and development opportunities
- A monthly stipend for your preferred co-working space
About OpenZeppelin
OpenZeppelin is the security standard for onchain finance, founded in 2015 to accelerate the world's transition to an open financial system. Their open-source Contract Libraries have facilitated over $35 trillion in onchain value and are used by 10 of the top 10 tokenized money market funds and 9 of the top 10 stablecoins by market cap. They combine AI-native security tooling with deep research and a decade of audit expertise to support leading institutions and crypto-native teams across the full secure development lifecycle.
What security roles in crypto pay
112 salaries · our own dataMost security roles in crypto pay between $141k and $264k, with a median of $195k.