OpenZeppelin logo

OpenZeppelin

Principal Security Engineer (Solana)

Undisclosed

Remote. The employer does not say where candidates may be based.

Location not stated

Employer listed it 2 weeks ago Β· Found 6h ago

Been open since 2 weeks ago, still being checked, but it has been live a while.

Salary

Not stated

Location

Location not stated

Timezone

Not stated

Contract

Full-time

Experience

Lead

Category

Software

This employer didn't state pay. Jobs like this usually pay around $200k–$275k a year, a typical range taken from 597 lead-level software roles on Nomaders that do state pay. It's a guide, not an offer.

Remote flexibility

Undisclosed

The listing is advertised as remote but does not state which countries or regions candidates may work from.

Why this role is Undisclosed

We only label a role Work from anywhere, Region restricted or Work from home when the employer's own wording says so. We checked this advert under our current rules and found no country or region eligibility requirement in it. We don't guess, so it stays Undisclosed until the employer publishes enough location information. Here is exactly what the advert left out.

  • Countries you can work from: Not stated. The advert only gives "Remote", which names no country you must live in.
  • Whether the work is remote: Never mentioned. The role reached us through a remote job board, but the advert itself doesn't say the work is remote.
  • Working hours: Not stated. No timezone overlap or set hours are mentioned, so assume nothing either way.

Worth a look all the same. Missing wording is usually a rushed job posting rather than a closed door, so ask where you can be based in your first message, before you write a tailored application.

What the employer says

  • Source listing states candidate location: "Remote"

What Nomaders makes of it

  • No residency or region requirement found in the job description
  • Check with the employer before assuming you can work from abroad

The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.

About the role

About us

OpenZeppelin is the security standard onchain finance is built on. Founded in 2015, our mission is to accelerate the world's transition to an open financial system, built on open standards and secured by rigorous research.

Our open-source Contract Libraries have facilitated over $35 trillion in onchain value and are used by 10 of the top 10 tokenized money market funds and 9 of the top 10 stablecoins by market cap.

We combine AI-native security tooling with deep research and a decade of audit expertise to support leading institutions and crypto-native teams shaping the next generation of digital assets like DTCC, Fidelity, Coinbase, Uniswap, Aave, the Ethereum Foundation, and many more across the full secure development lifecycle.

Please note: Always refer to OpenZeppelin's official job page for the most accurate information about our open roles, as we have seen multiple third party job sites posting inaccurate information.

The Secure Development team ❀️

OpenZeppelin is the security partner of choice for the most important protocols in Web3. Our Secure Development team sits at the intersection of building and breaking: we design, implement, and harden production-grade libraries and smart contracts for leading projects across EVM, Starknet, Stellar/Soroban, Arbitrum Stylus, Aptos, and beyond, often as an embedded extension of the client's engineering team.

We work the way the rest of the industry will five years from now. Every developer on the team is a fully AI-native engineer, supported by outstanding internal AI tooling built for every phase of secure development. Developers own their workstreams end-to-end β€” agents amplify their effectiveness, and peers, security researchers, and external auditors provide rigorous review on every piece of work that ships.

We are looking for a Principal Solana Developer to set the technical direction for our work on the SVM. This is not a seat on an existing Solana team: you are the person who defines what OpenZeppelin's Solana practice looks like, in the open and under your own name, so your reputation compounds with ours.

The engagement

Your first focus is our confidential computing track on Solana: porting onchain fully homomorphic encryption primitives to the SVM runtime, designing the confidential token standard and the SDK patterns on top of it, and building the developer abstractions that make it usable. It runs into 2027, it is public, and it is coordinated directly with the Solana Foundation. The open design questions are yours to own: access control list storage cost, program upgradability and governance, and how to express confidential DeFi flows idiomatically on Solana rather than transliterating them from EVM.

Beyond that engagement, you are the SVM technical lead across our portfolio: shaping how we scope and staff Solana audits, contributing to our open source libraries and tooling, and giving the security research team the depth they need when a program lands on their desk.

Within this, you will:

Lead our Solana workstreams end to end, from architecture and implementation through audit preparation, deployment and post launch hardening. You make the calls, and you bring others with you.

Build production grade programs and libraries where security is the primary constraint, not an afterthought. Most of your code will be reviewed by world class auditors.

Own the hard design questions of a young ecosystem: storage and compute cost models, upgradability and governance, and idiomatic patterns for primitives with no Solana precedent yet.

Run client facing roadmap and design discussions independently. You are the technical voice in the room, and the person a client's own engineers want to argue with.

Raise the level of everyone around you: review the team's Solana work, set the standards it is held to, and shorten the ramp for the people coming in behind you.

Represent OpenZeppelin in the ecosystem: engage with the Solana Foundation, core teams and standards discussions, publish the work, and contribute to our open source libraries and tooling.

Use AI as a core daily tool: build agents, skills and workflows that compound the team's leverage, apply it directly to security work, and share what works back to the team.

Collaborate with our blockchain security researchers on cross team research and protocol level threat analysis.

You have

3+ years building on Solana in production . Programs you shipped, that other people depend on. You can point at them.

Demonstrated ability to lead the work. You have owned the architecture and delivery of a multi quarter workstream, made the consequential technical calls, and carried them through review, disagreement and shipping. Leading here means owning technical direction and being the person others align to, not managing headcount.

Requirements

  • Β·3+ years building on Solana in production . Programs you shipped, that other people depend on. You can point at them.
  • Β·Contributions to standards. Solana Improvement Documents, SPL and Token 2022 extensions, or the Wallet Standard.
  • Β·Experience working alongside a foundation or core protocol team. The deliverable is a standard others adopt.
  • Β·Anchor and beneath it. You are productive in Anchor and equally comfortable working directly against the runtime when the situation calls for it. You know what each choice costs.
  • Β·A security first mindset. This is non negotiable. You think adversarially about every line of code you write, and you have demonstrable experience auditing, breaking or hardening production systems.

Benefits

  • Β·Meet your teammates at company gatherings around the world 😎
  • Β·Enjoy the flexibility of fully remote work 🌎
  • Β·Take the time you need with flexible time off 🏝
  • Β·Grow your family with 8 weeks of paid leave for primary caregivers, 4 weeks for secondary caregivers, and a one-time $3,600 baby bonus πŸ’™
  • Β·Build your ideal home office with up to $500 in equipment support πŸͺ‘

How to apply

  1. 1Check the flexibility label above, undisclosed, matches where you plan to live and work.
  2. 2Tailor your CV to the role at OpenZeppelin, mentioning your remote working experience.
  3. 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.

Found 7h ago. Last checked today. Always confirm the details on the original posting, salary and location can change after publication.

Listing sourced from Company boards.

Similar roles

Other open software roles with comparable remote rules.

Browse all open roles

Free to apply, no account needed.

Typically $200k to $275k per year Β· You'll be taken to the employer's careers page.