OpenZeppelin
Head of IT & Security
Remote. The employer does not say where candidates may be based.
Location not stated
Employer listed it 12 days ago Β· Found 7h ago
First listed 12 days ago and still open.
Salary
Not stated
Location
Location not stated
Timezone
Not stated
Contract
Full-time
Experience
Lead
Category
Software
This employer didn't state pay. Jobs like this usually pay around $200kβ$275k a year, a typical range taken from 597 lead-level software roles on Nomaders that do state pay. It's a guide, not an offer.
Remote flexibility
Undisclosed
The listing is advertised as remote but does not state which countries or regions candidates may work from.
Why this role is Undisclosed
We only label a role Work from anywhere, Region restricted or Work from home when the employer's own wording says so. We checked this advert under our current rules and found no country or region eligibility requirement in it. We don't guess, so it stays Undisclosed until the employer publishes enough location information. Here is exactly what the advert left out.
- Countries you can work from: Not stated. The advert only gives "Remote", which names no country you must live in.
- Whether the work is remote: Never mentioned. The role reached us through a remote job board, but the advert itself doesn't say the work is remote.
- Working hours: Not stated. No timezone overlap or set hours are mentioned, so assume nothing either way.
Worth a look all the same. Missing wording is usually a rushed job posting rather than a closed door, so ask where you can be based in your first message, before you write a tailored application.
What the employer says
- Source listing states candidate location: "Remote"
What Nomaders makes of it
- No residency or region requirement found in the job description
- Check with the employer before assuming you can work from abroad
The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.
About the role
About us
OpenZeppelin is the security standard onchain finance is built on. Founded in 2015, our mission is to accelerate the world's transition to an open financial system, built on open standards and secured by rigorous research.
Our open-source Contract Libraries have facilitated over $35 trillion in onchain value and are used by 10 of the top 10 tokenized money market funds and 9 of the top 10 stablecoins by market cap.
We combine AI-native security tooling with deep research and a decade of audit expertise to support leading institutions and crypto-native teams shaping the next generation of digital assets like DTCC, Fidelity, Coinbase, Uniswap, Aave, the Ethereum Foundation, and many more across the full secure development lifecycle.
Please note: Always refer to OpenZeppelin's official job page for the most accurate information about our open roles, as we have seen multiple third party job sites posting inaccurate information.
The IT & Security Team
The Information Security function operates independently under our Legal team and owns everything that keeps the OpenZeppelin organization secure. That means managing our Security, Privacy & IT Program end-to-end: our SOC 2 and ISO 27001 posture, vendor and privacy risk, incident response, our bug bounty programs, and the identity, endpoint, and access systems the whole company depends on. It is also the team our customers meet during security diligence. As our enterprise relationships deepen, increasingly with banks and other regulated institutions, our own program must be as credible as the security we deliver to customers.
Today that program is established and audit-ready. The next chapter is turning it into an enterprise-grade security function that stands up to the scrutiny of the most demanding enterprise customers, partners, and regulators, while safely accelerating our adoption of AI across the company.
What you'll be doing
You will own the strategy, design, and continuous maturation of OpenZeppelin's Information Security Program, and be accountable for managing the team executing it. You can issue-spot security and privacy risks before they materialize, explain the principles behind security and compliance controls to auditors and enterprise security teams, and calibrate our security program proportionate to risk.
IT and infrastructure: Oversee identity and access management, provisioning and onboarding/offboarding, end-user security (MDM, endpoint protection, security training), physical security, disaster recovery, business continuity, and data backup, using automation and AI-powered workflows to make IT and security operations scale faster than headcount.
Strategy, governance and budget: Set the strategic direction, multi-year roadmap, and risk posture of the Information Security Program; deliver on department OKRs; and own the IT and technology budget, with ultimate responsibility for technology procurement.
AI security and governance: Own the secure adoption of AI across the company: evolve our AI governance framework, review and approve AI tools and agentic workflows, and secure our agentic infrastructure (identity, least-privilege tool and data access, secrets handling, monitoring, auditability). Manage frontier model providers as critical vendors, covering security and data-handling diligence, retention and training-use commitments, DPAs and subprocessor flow-downs. Meet emerging obligations such as the EU AI Act, so we can make transparent, defensible commitments to enterprise customers about how our products and internal AI usage handle their data.
Compliance, audit and enterprise trust: Own our audit, certification, and attestation strategy and execution (penetration testing, SOC 2 Type 2, ISO/IEC 27001, successor frameworks) alongside internal security audits; run a third-party and vendor risk management program; and serve as the external face of our security program with customer security teams, regulated financial institutions, and auditors.
Privacy and data governance: Maintain a comprehensive data map of how data flows into, through, and out of the organization, including flows to model providers and through agentic workflows, with data classification, records of processing, and a vendor/subprocessor inventory. Own privacy compliance in partnership with Legal: GDPR, CCPA/CPRA, DPAs and contractual security commitments, and privacy-by-design reviews of new products and features.
Security operations and incident response: Own the incident response program end-to-end, including playbooks, tabletop exercises, post-incident reviews, and breach-notification obligations in partnership with Legal. Manage our bug bounty programs, and partner with development teams to embed security best practices in the SDLC and our software offerings.
You have
10+ years of Security and IT experience, including 3+ years leading a IT Security and GRC function (not solely IT operations) in a high-growth tech company, with demonstrated ownership of strategy, not just execution.
A demonstrated trajectory toward CISO: you have owned a security program end-to-end, presented to executives or boards, and can articulate the "why" behind every control you have implemented.
Experience securing or governing AI/LLM-enabled products or enterprise AI adoption including agentic systems and third-party model-provider risk, with an ability to apply privacy and data-protection laws and practices (e.g., GDPR, CCPA/CPRA) in the AI context.
Nice to have
5+ years working in blockchain or a FinTech with an enterprise client base (e.g., financial services), including navigating rigorous third-party security diligence.
Logistics:
Our interview process takes place on Google Meet or Zoom and tends to consist of the following stages:
Requirements
- Β·10+ years of Security and IT experience, including 3+ years leading a IT Security and GRC function (not solely IT operations) in a high-growth tech company, with demonstrated ownership of strategy, not just execution.
- Β·A demonstrated trajectory toward CISO: you have owned a security program end-to-end, presented to executives or boards, and can articulate the "why" behind every control you have implemented.
- Β·5+ years working in blockchain or a FinTech with an enterprise client base (e.g., financial services), including navigating rigorous third-party security diligence.
Benefits
- Β·Meet your teammates at company gatherings around the world π
- Β·Enjoy the flexibility of fully remote work π
- Β·Take the time you need with flexible time off π
- Β·Grow your family with 8 weeks of paid leave for primary caregivers, 4 weeks for secondary caregivers, and a one-time $3,600 baby bonus π
- Β·Build your ideal home office with up to $500 in equipment support πͺ
How to apply
- 1Check the flexibility label above, undisclosed, matches where you plan to live and work.
- 2Tailor your CV to the role at OpenZeppelin, mentioning your remote working experience.
- 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.
Found 8h ago. Last checked today. Always confirm the details on the original posting, salary and location can change after publication.
Listing sourced from Company boards.
Similar roles
Other open software roles with comparable remote rules.
Free to apply, no account needed.
Typically $200k to $275k per year Β· You'll be taken to the employer's careers page.