
11 - 50 employees
Founded 2015
đŒ Consulting
đŠ Logistics
đŁ Marketing
đ° Seed Round on 2018-01
Consulting âą Logistics âą Marketing
OpenZeppelin is a leading provider of open-source tools and services that secure and streamline smart contract development. They offer a comprehensive suite of solutions, including a secure smart contract library, an interactive smart contract generator (Contracts Wizard), and a defender cloud service for monitoring, automating, and upgrading smart contracts. OpenZeppelin's services include smart contract security audits and emergency response teams to address vulnerabilities promptly. Their ecosystem stack accelerates developer onboarding and ensures high security standards are met in decentralized applications. Trusted by major decentralized projects, OpenZeppelin is a standard-bearer in the blockchain space, focusing on security, scalability, and privacy in smart contract and onchain applications development.
đ„ 9 hours ago
đ Anywhere in the World
â° Full Time
đŽ Lead
đźââïž Cybersecurity / Security Engineer
đ» Ghost score 10%
Improve your chances of getting an interview by checking your resume score before you apply.

11 - 50 employees
Founded 2015
đŒ Consulting
đŠ Logistics
đŁ Marketing
đ° Seed Round on 2018-01
Consulting âą Logistics âą Marketing
OpenZeppelin is a leading provider of open-source tools and services that secure and streamline smart contract development. They offer a comprehensive suite of solutions, including a secure smart contract library, an interactive smart contract generator (Contracts Wizard), and a defender cloud service for monitoring, automating, and upgrading smart contracts. OpenZeppelin's services include smart contract security audits and emergency response teams to address vulnerabilities promptly. Their ecosystem stack accelerates developer onboarding and ensures high security standards are met in decentralized applications. Trusted by major decentralized projects, OpenZeppelin is a standard-bearer in the blockchain space, focusing on security, scalability, and privacy in smart contract and onchain applications development.
âą Own the strategy, design, and continuous maturation of OpenZeppelin's Information Security Program âą Manage the team executing the Information Security Program âą Set strategic direction, multi-year roadmap, and risk posture; deliver department OKRs âą Own the IT and technology budget and technology procurement âą Lead secure adoption of AI, including AI governance, AI tool and agentic workflow reviews, and agentic infrastructure security âą Manage frontier model providers as critical vendors, including security and data-handling diligence, retention and training-use commitments, DPAs, and subprocessor flow-downs âą Address emerging obligations such as the EU AI Act âą Own audit, certification, and attestation strategy and execution, including penetration testing, SOC 2 Type 2, and ISO/IEC 27001 âą Run third-party and vendor risk management âą Represent the security program to customer security teams, regulated financial institutions, and auditors âą Maintain data maps, data classification, records of processing, and vendor/subprocessor inventory âą Own privacy compliance with Legal, including GDPR, CCPA/CPRA, DPAs, contractual security commitments, and privacy-by-design reviews âą Own incident response, including playbooks, tabletop exercises, post-incident reviews, and breach notifications âą Manage bug bounty programs and partner with development teams on SDLC security âą Oversee identity and access management, provisioning, onboarding/offboarding, endpoint security, physical security, disaster recovery, business continuity, and backups âą Use automation and AI-powered workflows to scale IT and security operations
âą 10+ years of Security and IT experience âą 3+ years leading an IT Security and GRC function, not solely IT operations, in a high-growth tech company âą Demonstrated ownership of security strategy, not just execution âą Trajectory toward CISO, including end-to-end ownership of a security program âą Experience presenting to executives or boards âą Ability to articulate the rationale behind implemented controls âą Experience securing or governing AI/LLM-enabled products or enterprise AI adoption, including agentic systems and third-party model-provider risk âą Ability to apply privacy and data-protection laws and practices, including GDPR and CCPA/CPRA, in the AI context âą 5+ years working in blockchain or FinTech with an enterprise client base, including rigorous third-party security diligence (nice to have)
âą Meet your teammates at company gatherings around the world đ âą Enjoy the flexibility of fully remote work đ âą Take the time you need with flexible time off đ âą 8 weeks of paid leave for primary caregivers âą 4 weeks of paid leave for secondary caregivers âą One-time $3,600 baby bonus đ âą Up to $500 in equipment support for a home office đȘ âą Medical insurance đ„ âą Learning and development opportunities đ§ âą Monthly stipend for a preferred co-working space đ» âą Paid work test (up to 20 hours of paid work)
Apply Now