Principal Security Engineer (Solana) - OpenZeppelin

Fully remote

Added
Locations
Type
Full-time

About us

OpenZeppelin is the security standard onchain finance is built on. Founded in 2015, our mission is to accelerate the world's transition to an open financial system, built on open standards and secured by rigorous research.

Our open-source Contract Libraries have facilitated over $35 trillion in onchain value and are used by 10 of the top 10 tokenized money market funds and 9 of the top 10 stablecoins by market cap.

We combine AI-native security tooling with deep research and a decade of audit expertise to support leading institutions and crypto-native teams shaping the next generation of digital assets like DTCC, Fidelity, Coinbase, Uniswap, Aave, the Ethereum Foundation, and many more across the full secure development lifecycle.

Please note: Always refer to OpenZeppelin's official job page for the most accurate information about our open roles, as we have seen multiple third party job sites posting inaccurate information.

The Secure Development team ❤️

OpenZeppelin is the security partner of choice for the most important protocols in Web3. Our Secure Development team sits at the intersection of building and breaking: we design, implement, and harden production-grade libraries and smart contracts for leading projects across EVM, Starknet, Stellar/Soroban, Arbitrum Stylus, Aptos, and beyond, often as an embedded extension of the client's engineering team.

We work the way the rest of the industry will five years from now. Every developer on the team is a fully AI-native engineer, supported by outstanding internal AI tooling built for every phase of secure development. Developers own their workstreams end-to-end — agents amplify their effectiveness, and peers, security researchers, and external auditors provide rigorous review on every piece of work that ships.

We are looking for a Principal Solana Developer to set the technical direction for our work on the SVM. This is not a seat on an existing Solana team: you are the person who defines what OpenZeppelin's Solana practice looks like, in the open and under your own name, so your reputation compounds with ours.

The engagement

Your first focus is our confidential computing track on Solana: porting onchain fully homomorphic encryption primitives to the SVM runtime, designing the confidential token standard and the SDK patterns on top of it, and building the developer abstractions that make it usable. It runs into 2027, it is public, and it is coordinated directly with the Solana Foundation. The open design questions are yours to own: access control list storage cost, program upgradability and governance, and how to express confidential DeFi flows idiomatically on Solana rather than transliterating them from EVM.

Beyond that engagement, you are the SVM technical lead across our portfolio: shaping how we scope and staff Solana audits, contributing to our open source libraries and tooling, and giving the security research team the depth they need when a program lands on their desk.

Within this, you will:

  • Lead our Solana workstreams end to end, from architecture and implementation through audit preparation, deployment and post launch hardening. You make the calls, and you bring others with you.
  • Build production grade programs and libraries where security is the primary constraint, not an afterthought. Most of your code will be reviewed by world class auditors.
  • Own the hard design questions of a young ecosystem: storage and compute cost models, upgradability and governance, and idiomatic patterns for primitives with no Solana precedent yet.
  • Run client facing roadmap and design discussions independently. You are the technical voice in the room, and the person a client's own engineers want to argue with.
  • Raise the level of everyone around you: review the team's Solana work, set the standards it is held to, and shorten the ramp for the people coming in behind you.
  • Represent OpenZeppelin in the ecosystem: engage with the Solana Foundation, core teams and standards discussions, publish the work, and contribute to our open source libraries and tooling.
  • Use AI as a core daily tool: build agents, skills and workflows that compound the team's leverage, apply it directly to security work, and share what works back to the team.
  • Collaborate with our blockchain security researchers on cross team research and protocol level threat analysis.

You have

  • 3+ years building on Solana in production. Programs you shipped, that other people depend on. You can point at them.
  • Demonstrated ability to lead the work. You have owned the architecture and delivery of a multi quarter workstream, made the consequential technical calls, and carried them through review, disagreement and shipping. Leading here means owning technical direction and being the person others align to, not managing headcount.
  • Deep SVM fluency. The account model, program derived addresses, cross program invocation, compute budgeting, rent and account lifecycle, versioned transactions and address lookup tables, and program upgradability along with its governance implications. You reason about Solana's constraints natively, not by analogy to the EVM.
  • Anchor and beneath it. You are productive in Anchor and equally comfortable working directly against the runtime when the situation calls for it. You know what each choice costs.
  • A security first mindset. This is non negotiable. You think adversarially about every line of code you write, and you have demonstrable experience auditing, breaking or hardening production systems.
  • An AI native workflow. Claude Code, Cursor or equivalent is your daily driver. You have measurable productivity gains to show for it, clear opinions on how to use these tools well, and you have shipped at least one non trivial AI powered tool, agent or automation pipeline in production, using the Anthropic SDK, MCP, custom evals or comparable.
  • Fluency in client facing communication (English). You can run a roadmap call, defend a design decision, and translate technical depth for a non technical stakeholder, in writing and live.
  • Alignment with OpenZeppelin's values. Intellectual curiosity, strong sense of purpose, attention to detail, and the ability to thrive in a fully distributed team.

Nice to have

  • Contributions to standards. Solana Improvement Documents, SPL and Token 2022 extensions, or the Wallet Standard.
  • Public standing in the Solana ecosystem. Widely used programs or tooling, published research, or conference talks.
  • Cryptography background. Fully homomorphic encryption, zero knowledge systems, or applied cryptography.
  • Compute unit and cost optimization depth. Low overhead runtimes such as Pinocchio, or a record of making expensive programs cheap.
  • Prior audit or security research output. Published reports, CTF participation, responsible disclosures, or security tooling.
  • Experience applying AI to security work. Audit assistance, vulnerability research, fuzzing, invariant or spec analysis.
  • Hands-on experience with other non-EVM ecosystems. Move based chains, Stellar and Soroban, Arbitrum Stylus, Starknet.
  • Experience working alongside a foundation or core protocol team. The deliverable is a standard others adopt.

Logistics

Our interview process is designed to be fast (we're targeting ~30 days from first call to offer) while still giving both sides a clear "yes." The full process consists of:

  • Recruiter interview (30-45 minutes)
  • Manager interview (60 minutes)
  • Leadership interview (30 minutes)
  • Paid technical work trial
  • Offer

Please let us know if you require any accommodations for the interview process, and we’ll do our best to provide assistance.

Benefits

  • Meet your teammates at company gatherings around the world 😎
  • Enjoy the flexibility of fully remote work 🌎
  • Take the time you need with flexible time off 🏝
  • Grow your family with 8 weeks of paid leave for primary caregivers, 4 weeks for secondary caregivers, and a one-time $3,600 baby bonus 💙
  • Build your ideal home office with up to $500 in equipment support 🪑
  • Stay covered with medical insurance 🏥
  • Keep growing with learning and development opportunities 🧠
  • Get a monthly stipend for your preferred co-working space 💻

At OpenZeppelin, we are an equal opportunity employer and we value different perspectives. We are committed to building a diverse workforce. This includes but is not limited to gender, race, sexual orientation, religion, national origin and other characteristics that make each one of us unique. In this uniqueness, we find the most value. Come join us!

Use of AI as part of the recruiting process

As part of OpenZeppelin’s recruitment process, we may use automated tools, including artificial intelligence, to assist in reviewing applications and assessing candidate qualifications. These tools are used to support our People team by identifying relevant skills and experience, and are not used to make decisions solely by automated means. All hiring decisions involve human review. Any personal data provided as part of your application will be processed in accordance with OpenZeppelin’s Data Privacy Notice.

If you have questions about this recruitment process or would like to request human review of your application, please contact us at talent@openzeppelin.com.

Share job

Want to learn more about how the process works?

Read the documentation for information on the application process.

View Documentation
Apply at OpenZeppelin
Apply Now →