Log inPost your job
← All jobs
OP

Principal Security Engineer (Solana)

OpenZeppelinUnited States
SecuritySeniorRemote
🌍 Fully remote🏖 Unlimited / flexible time off

As Principal Security Engineer (Solana) at OpenZeppelin, you set the technical direction for OpenZeppelin's work on the Solana Virtual Machine. You are not joining an existing team: you define what OpenZeppelin's Solana practice looks like, in the open and under your own name. Your first focus is a confidential computing track on Solana, porting onchain fully homomorphic encryption primitives to the SVM runtime, designing the confidential token standard and SDK patterns, and building developer abstractions to make it usable. Beyond that, you are the SVM technical lead across OpenZeppelin's portfolio, shaping how the team scopes and staffs Solana audits, contributing to open source libraries and tooling, and giving the security research team the depth they need.

What you'll do

  • Lead Solana workstreams end to end, from architecture and implementation through audit preparation, deployment and post-launch hardening, making consequential technical calls and bringing others with you.
  • Build production-grade programs and libraries where security is the primary constraint, with most code reviewed by world-class auditors.
  • Own the hard design questions of a young ecosystem: storage and compute cost models, upgradability and governance, and idiomatic patterns for primitives with no Solana precedent yet.
  • Run client-facing roadmap and design discussions independently as the technical voice in the room.
  • Raise the level of everyone around you by reviewing the team's Solana work, setting standards, and shortening the ramp for incoming engineers.
  • Represent OpenZeppelin in the ecosystem: engage with the Solana Foundation, core teams and standards discussions, publish the work, and contribute to open source libraries and tooling.
  • Use AI as a core daily tool to build agents, skills and workflows that compound team leverage, apply it directly to security work, and share learnings back to the team.
  • Collaborate with blockchain security researchers on cross-team research and protocol-level threat analysis.

What you bring

  • 3+ years building on Solana in production with programs you shipped that other people depend on.
  • Demonstrated ability to lead work: you have owned the architecture and delivery of a multi-quarter workstream, made consequential technical calls, and carried them through review, disagreement and shipping.
  • Deep SVM fluency in the account model, program-derived addresses, cross-program invocation, compute budgeting, rent and account lifecycle, versioned transactions, address lookup tables, and program upgradability with its governance implications.
  • Contributions to standards such as Solana Improvement Documents, SPL and Token 2022 extensions, or the Wallet Standard.
  • Experience working alongside a foundation or core protocol team where the deliverable is a standard others adopt.
  • Proficiency in Anchor and the ability to work directly against the runtime when needed, understanding the cost of each choice.
  • A security-first mindset that is non-negotiable: you think adversarially about every line of code, with demonstrable experience auditing, breaking or hardening production systems.
  • An AI-native workflow: Claude Code, Cursor or equivalent is your daily driver, with measurable productivity gains to show, clear opinions on tool use, and at least one non-trivial AI-powered tool, agent or automation pipeline shipped in production using the Anthropic SDK, MCP, custom evals or comparable.
  • Fluency in client-facing communication in English: you can run roadmap calls, defend design decisions, and translate technical depth for non-technical stakeholders both in writing and live.
  • Alignment with OpenZeppelin's values: intellectual curiosity, strong sense of purpose, attention to detail, and ability to thrive in a fully distributed team.

Nice to have

  • Public standing in the Solana ecosystem through widely used programs or tooling, published research, or conference talks.
  • Cryptography background in fully homomorphic encryption, zero-knowledge systems, or applied cryptography.
  • Compute unit and cost optimization depth, including experience with low-overhead runtimes such as Pinocchio or a record of making expensive programs cheap.
  • Prior audit or security research output such as published reports, CTF participation, responsible disclosures, or security tooling.
  • Experience applying AI to security work: audit assistance, vulnerability research, fuzzing, invariant or spec analysis.
  • Hands-on experience with other non-EVM ecosystems such as move-based chains, Stellar and Soroban, Arbitrum Stylus, or Starknet.

What we offer

  • Fully remote work with the flexibility to meet teammates at company gatherings around the world.
  • Flexible time off.
  • 8 weeks of paid leave for primary caregivers, 4 weeks for secondary caregivers, and a one-time $3,600 baby bonus.
  • Up to $500 in home office equipment support.
  • Medical insurance.
  • Learning and development opportunities.
  • Monthly stipend for a preferred co-working space.

About OpenZeppelin

OpenZeppelin is the security standard onchain finance is built on. Founded in 2015, the company has facilitated over $35 trillion in onchain value through open-source Contract Libraries used by 10 of the top 10 tokenized money market funds and 9 of the top 10 stablecoins by market cap. OpenZeppelin combines AI-native security tooling with deep research and a decade of audit expertise to support leading institutions and crypto-native teams including DTCC, Fidelity, Coinbase, Uniswap, Aave, the Ethereum Foundation, and more across the full secure development lifecycle.

What security roles in crypto pay

114 salaries · our own data
median $195k$140k$264k

Most security roles in crypto pay between $140k and $264k, with a median of $195k.

Principal Security Engineer (Solana) | CryptoJobsHQ