Senior Blockchain Security Developer (Canton)
What security roles in crypto pay
75 salaries · our own dataMost security roles in crypto pay between $145k and $268k, with a median of $200k.
As a Senior Blockchain Security Developer at OpenZeppelin, you'll join the Secure Development team to build production-grade smart contracts and libraries for the Canton Network, a privacy-preserving institutional blockchain. Over a 24-month engagement, you'll own features of the OpenZeppelin Contracts Library for Daml, design and implement privacy-preserving DeFi components, and help establish Canton as the security standard for the next generation of digital assets.
What you'll do
- Own features of the OpenZeppelin Contracts Library for Daml end to end, from design through audit, such as Timelock, access control, vaults, or token standard support.
- Design and implement components of the year-1 Reference Implementations, including a privacy-preserving DEX, lending protocol, cross-chain stablecoin settlement, and confidential auction launchpad.
- Implement and shepherd the OpenZeppelin Daml versions of CIP-56, CIP-86, CIP-103, and future CIPs, coordinating with Digital Asset on spec evolution and with ChainSafe on middleware alignment.
- Present and defend your designs in technical discussions with Digital Asset, the Canton Foundation, and other partners.
- Work with OpenZeppelin's security researchers on threat models, audit preparation, and fixes for the components you own.
- Use AI systems as core daily tools for research, design, implementation, testing, and security work, including building agents, skills, and workflows to share with the team.
- Contribute developer-experience and security feedback upstream into the Canton protocol, Splice, the Daml SDK, and the Splice Wallet Kernel.
- Research privacy-preserving DeFi, multi-party authorization patterns, and Canton-specific primitives, and share your findings with the team.
What you bring
- Production Daml fluency: you understand templates, choices, controllers/observers/signatories, multi-party authorization, sub-transaction views, and propose/accept patterns as first-class primitives.
- Canton architecture depth: you understand the network at a deep level, including the Global Synchronizer and private synchronizers, what each party sees in a transaction, smart contract upgrades, and the token standards (CIP-56, CIP-112).
- 3+ years of smart contract development in production, including hands-on work on Canton or another UTXO-based or privacy-preserving architecture such as Cardano, Midnight, Zcash, Aleo, or Mina.
- Production DeFi experience: you have shipped DeFi primitives such as AMMs, vaults (ERC-4626 or equivalent), lending protocols, or cross-chain settlement, and you understand the security pitfalls of each.
- A security-first mindset that is non-negotiable: you build secure code by default, think adversarially about every line you write, and find vulnerabilities when reviewing Daml code.
- An AI-native workflow: tools like Claude Code or Cursor are your daily driver, you understand agents and harnesses, and you hold AI output to the same standard as a colleague's pull request.
- Fluency in client-facing communication in English.
- Autonomy and proactivity in your work.
Nice to have
- A cryptography or financial-engineering background.
- Institutional finance and compliance design experience, including credential gates, multi-party attestation, custody flows, capital-markets microstructure, RWA tokenization, or settlement.
- Experience running a Splice Validator, contributing to Splice internals, governance, or Canton Coin tokenomics.
- Cross-chain interoperability exposure with at least one major cross-chain messaging protocol such as Chainlink CCIP, LayerZero, Wormhole, or Axelar.
- Library or SDK API design experience: you've built reusable, import-first developer libraries and have opinions on extensibility patterns and what makes an audited primitive pleasant to consume.
- Experience applying AI to security work, such as audit assistance, vulnerability research, fuzzing, invariant or spec analysis, or static-analysis augmentation.
- Hands-on experience with non-EVM ecosystems such as Starknet, Stellar/Soroban, Arbitrum Stylus, Aptos, or Move-based chains.
- Open-source contributions to widely-used libraries in the smart-contract or AI-tooling space.
What we offer
- Fully remote work with the flexibility to meet your teammates at company gatherings around the world.
- Flexible time off so you can take the time you need.
- 8 weeks of paid leave for primary caregivers and 4 weeks for secondary caregivers, plus a one-time $3,600 baby bonus.
- Up to $500 in equipment support to build your ideal home office.
- Medical insurance coverage.
- Learning and development opportunities to grow your skills.
- A monthly stipend for your preferred co-working space.
About OpenZeppelin
OpenZeppelin is the security standard onchain finance is built on. Founded in 2015, the company combines AI-native security tooling with deep research and a decade of audit expertise to support leading institutions and crypto-native teams across the full secure development lifecycle. OpenZeppelin's open-source Contract Libraries have facilitated over $35 trillion in onchain value and are used by 10 of the top 10 tokenized money market funds and 9 of the top 10 stablecoins by market cap.
