Principal Security Engineer (Solana)
OpenZeppelin is the security standard onchain finance is built on. Founded in 2015, our mission is to accelerate the world's transition to an open financial system, built on open standards and secured by rigorous research. Our open-source Contract Libraries have facilitated over $35 trillion in onchain value and are used by 10 of the top 10 tokenized money market funds and 9 of the top 10 stablecoins by market cap. We combine AI-native security tooling with deep research and a decade of audit expertise to support leading institutions and crypto-native teams shaping the next generation of digital assets.
About the role
The Secure Development team at OpenZeppelin sits at the intersection of building and breaking: we design, implement, and harden production-grade libraries and smart contracts for leading projects across EVM, Starknet, Stellar/Soroban, Arbitrum Stylus, Aptos, and beyond, often as an embedded extension of the client's engineering team. We work the way the rest of the industry will five years from now, with every developer on the team being a fully AI-native engineer supported by outstanding internal AI tooling.
We are looking for a Principal Solana Developer to set the technical direction for our work on the SVM. This is not a seat on an existing Solana team: you are the person who defines what OpenZeppelin's Solana practice looks like, in the open and under your own name, so your reputation compounds with ours.
Responsibilities
- Lead our Solana workstreams end to end, from architecture and implementation through audit preparation, deployment and post launch hardening. You make the calls, and you bring others with you.
- Build production grade programs and libraries where security is the primary constraint, not an afterthought. Most of your code will be reviewed by world class auditors.
- Own the hard design questions of a young ecosystem: storage and compute cost models, upgradability and governance, and idiomatic patterns for primitives with no Solana precedent yet.
- Run client facing roadmap and design discussions independently. You are the technical voice in the room, and the person a client's own engineers want to argue with.
- Raise the level of everyone around you: review the team's Solana work, set the standards it is held to, and shorten the ramp for the people coming in behind you.
- Represent OpenZeppelin in the ecosystem: engage with the Solana Foundation, core teams and standards discussions, publish the work, and contribute to our open source libraries and tooling.
- Use AI as a core daily tool: build agents, skills and workflows that compound the team's leverage, apply it directly to security work, and share what works back to the team.
- Collaborate with our blockchain security researchers on cross team research and protocol level threat analysis.
Requirements
- 3+ years building on Solana in production. Programs you shipped, that other people depend on. You can point at them.
- Demonstrated ability to lead the work. You have owned the architecture and delivery of a multi-quarter workstream, made the consequential technical calls, and carried them through review, disagreement and shipping. Leading here means owning technical direction and being the person others align to, not managing headcount.
- Deep SVM fluency. The account model, program derived addresses, cross program invocation, compute budgeting, rent and account lifecycle, versioned transactions and address lookup tables, and program upgradability along with its governance implications. You reason about Solana's constraints natively, not by analogy to the EVM.
- Anchor and beneath it. You are productive in Anchor and equally comfortable working directly against the runtime when the situation calls for it. You know what each choice costs.
- A security first mindset. This is non-negotiable. You think adversarially about every line of code you write, and you have demonstrable experience auditing, breaking or hardening production systems.
- An AI native workflow. Claude Code, Cursor or equivalent is your daily driver. You have measurable productivity gains to show for it, clear opinions on how to use these tools well, and you have shipped at least one non-trivial AI powered tool, agent or automation pipeline in production, using the Anthropic SDK, MCP, custom evals or comparable.
- Fluency in client facing communication (English). You can run a roadmap call, defend a design decision, and translate technical depth for a non-technical stakeholder, in writing and live.
- Alignment with OpenZeppelin's values: intellectual curiosity, strong sense of purpose, attention to detail, and the ability to thrive in a fully distributed team.
Nice to have
- Contributions to standards. Solana Improvement Documents, SPL and Token 2022 extensions, or the Wallet Standard.
- Public standing in the Solana ecosystem. Widely used programs or tooling, published research, or conference talks.
- Cryptography background. Fully homomorphic encryption, zero knowledge systems, or applied cryptography.
- Compute unit and cost optimization depth. Low overhead runtimes such as Pinocchio, or a record of making expensive programs cheap.
- Prior audit or security research output. Published reports, CTF participation, responsible disclosures, or security tooling.
- Experience applying AI to security work. Audit assistance, vulnerability research, fuzzing, invariant or spec analysis.
- Hands-on experience with other non-EVM ecosystems. Move based chains, Stellar and Soroban, Arbitrum Stylus, Starknet.
- Experience working alongside a foundation or core protocol team. The deliverable is a standard others adopt.
The engagement
Your first focus is our confidential computing track on Solana: porting onchain fully homomorphic encryption primitives to the SVM runtime, designing the confidential token standard and the SDK patterns on top of it, and building the developer abstractions that make it usable. It runs into 2027, it is public, and it is coordinated directly with the Solana Foundation. The open design questions are yours to own: access control list storage cost, program upgradability and governance, and how to express confidential DeFi flows idiomatically on Solana rather than transliterating them from EVM.
Beyond that engagement, you are the SVM technical lead across our portfolio: shaping how we scope and staff Solana audits, contributing to our open source libraries and tooling, and giving the security research team the depth they need when a program lands on their desk.
Benefits
- Meet your teammates at company gatherings around the world
- Enjoy the flexibility of fully remote work
- Take the time you need with flexible time off
- Grow your family with 8 weeks of paid leave for primary caregivers, 4 weeks for secondary caregivers, and a one-time $3,600 baby bonus
- Build your ideal home office with up to $500 in equipment support
- Stay covered with medical insurance
- Keep growing with learning and development opportunities
- Get a monthly stipend for your preferred co-working space