Build your online resume. Claim your username
OpenZeppelin logo

Head of IT and Information Security at OpenZeppelin

Remote 🌍 Work from Anywhere Full time Executive Posted  Apply before Nov 10, 2026

Job Description

About OpenZeppelin

OpenZeppelin is the security standard onchain finance is built on. Founded in 2015, the mission is to accelerate the world's transition to an open financial system, built on open standards and secured by rigorous research. The open-source Contract Libraries have facilitated over $35 trillion in onchain value and are used by 10 of the top 10 tokenized money market funds and 9 of the top 10 stablecoins by market cap. The company combines AI-native security tooling with deep research and a decade of audit expertise to support leading institutions and crypto-native teams shaping the next generation of digital assets, including DTCC, Fidelity, Coinbase, Uniswap, Aave, and the Ethereum Foundation.

The IT and Security Team

The Information Security function operates independently under the Legal team and owns everything that keeps the OpenZeppelin organization secure, managing the Security, Privacy and IT Program end to end: SOC 2 and ISO 27001 posture, vendor and privacy risk, incident response, bug bounty programs, and the identity, endpoint, and access systems the whole company depends on. It is also the team customers meet during security diligence. As enterprise relationships deepen, increasingly with banks and other regulated institutions, the program must be as credible as the security delivered to customers. Today the program is established and audit-ready; the next chapter is turning it into an enterprise-grade security function that stands up to the scrutiny of the most demanding enterprise customers, partners, and regulators, while safely accelerating adoption of AI across the company.

What You Will Be Doing

You will own the strategy, design, and continuous maturation of OpenZeppelin's Information Security Program, and be accountable for managing the team executing it. You can spot security and privacy risks before they materialize, explain the principles behind security and compliance controls to auditors and enterprise security teams, and calibrate the security program proportionate to risk.

  • IT and infrastructure: Oversee identity and access management, provisioning and onboarding/offboarding, end-user security (MDM, endpoint protection, security training), physical security, disaster recovery, business continuity, and data backup, using automation and AI-powered workflows to make IT and security operations scale faster than headcount.
  • Strategy, governance and budget: Set the strategic direction, multi-year roadmap, and risk posture of the Information Security Program; deliver on department OKRs; and own the IT and technology budget, with ultimate responsibility for technology procurement.
  • AI security and governance: Own the secure adoption of AI across the company: evolve the AI governance framework, review and approve AI tools and agentic workflows, and secure agentic infrastructure (identity, least-privilege tool and data access, secrets handling, monitoring, auditability). Manage frontier model providers as critical vendors, covering security and data-handling diligence, retention and training-use commitments, DPAs and subprocessor flow-downs. Meet emerging obligations such as the EU AI Act so the company can make transparent, defensible commitments to enterprise customers about how products and internal AI usage handle their data.
  • Compliance, audit and enterprise trust: Own the audit, certification, and attestation strategy and execution (penetration testing, SOC 2 Type 2, ISO/IEC 27001, successor frameworks) alongside internal security audits; run a third-party and vendor risk management program; and serve as the external face of the security program with customer security teams, regulated financial institutions, and auditors.
  • Privacy and data governance: Maintain a comprehensive data map of how data flows into, through, and out of the organization, including flows to model providers and through agentic workflows, with data classification, records of processing, and a vendor/subprocessor inventory. Own privacy compliance in partnership with Legal: GDPR, CCPA/CPRA, DPAs and contractual security commitments, and privacy-by-design reviews of new products and features.
  • Security operations and incident response: Own the incident response program end to end, including playbooks, tabletop exercises, post-incident reviews, and breach-notification obligations in partnership with Legal. Manage bug bounty programs, and partner with development teams to embed security best practices in the SDLC and software offerings.

You Have

  • 10+ years of Security and IT experience, including 3+ years leading an IT Security and GRC function (not solely IT operations) in a high-growth tech company, with demonstrated ownership of strategy, not just execution.
  • A demonstrated trajectory toward CISO: you have owned a security program end to end, presented to executives or boards, and can articulate the reasoning behind every control you have implemented.
  • Experience securing or governing AI/LLM-enabled products or enterprise AI adoption, including agentic systems and third-party model-provider risk, with an ability to apply privacy and data-protection laws and practices (e.g., GDPR, CCPA/CPRA) in the AI context.

Nice to Have

  • 5+ years working in blockchain or a FinTech with an enterprise client base (e.g., financial services), including navigating rigorous third-party security diligence.

Interview Process

Our interview process takes place on Google Meet or Zoom and tends to consist of the following stages:

  • Recruiter Call (30 minutes)
  • Hiring Manager Call (30 minutes)
  • Team Interview (30 minutes)
  • Leadership Interview (30 minutes)
  • Paid work test (up to 20 hours of paid work)
  • Reference checks

Benefits

  • Meet your teammates at company gatherings around the world
  • Enjoy the flexibility of fully remote work
  • Take the time you need with flexible time off
  • Grow your family with 8 weeks of paid leave for primary caregivers, 4 weeks for secondary caregivers, and a one-time $3,600 baby bonus
  • Build your ideal home office with up to $500 in equipment support
  • Stay covered with medical insurance
  • Keep growing with learning and development opportunities
  • Get a monthly stipend for your preferred co-working space

OpenZeppelin is an equal opportunity employer and values different perspectives, committed to building a diverse workforce. This includes but is not limited to gender, race, sexual orientation, religion, national origin and other characteristics that make each one of us unique. In this uniqueness, the greatest value is found.

Use of AI in the Recruiting Process

As part of OpenZeppelin's recruitment process, automated tools, including artificial intelligence, may be used to assist in reviewing applications and assessing candidate qualifications. These tools are used to support the People team by identifying relevant skills and experience, and are not used to make decisions solely by automated means. All hiring decisions involve human review. Any personal data provided as part of an application will be processed in accordance with OpenZeppelin's Data Privacy Notice. If you have questions about this recruitment process or would like to request human review of your application, please contact [email protected].

Ready to Apply?

Take the next step in your career journey.

Apply Now

You will be redirected to the company's application page

💜 Please mention that you found the job on True Work From Home, this helps us grow. Thanks!