ForgeApply
Try it free

ForgeApply · Job listing

Principal Security Engineer (Solana)

Openzeppelin

Remote · US

Tailor your resume for this Openzeppelin job in about a minute.

ForgeApply rewrites your resume for this exact posting, then autofills the application on Openzeppelin's site with it. You review everything before it's sent. Free trial, no card required.

About this role

About us

OpenZeppelin is the security standard onchain finance is built on. Founded in 2015, our mission is to accelerate the world's transition to an open financial system, built on open standards and secured by rigorous research.

Our open-source Contract Libraries have facilitated over $35 trillion in onchain value and are used by 10 of the top 10 tokenized money market funds and 9 of the top 10 stablecoins by market cap.

We combine AI-native security tooling with deep research and a decade of audit expertise to support leading institutions and crypto-native teams shaping the next generation of digital assets like DTCC, Fidelity, Coinbase, Uniswap, Aave, the Ethereum Foundation, and many more across the full secure development lifecycle.

Please note: Always refer to OpenZeppelin's official job page for the most accurate information about our open roles, as we have seen multiple third party job sites posting inaccurate information.

The Secure Development team ❤️

OpenZeppelin is the security partner of choice for the most important protocols in Web3. Our Secure Development team sits at the intersection of building and breaking: we design, implement, and harden production-grade libraries and smart contracts for leading projects across EVM, Starknet, Stellar/Soroban, Arbitrum Stylus, Aptos, and beyond, often as an embedded extension of the client's engineering team.

We work the way the rest of the industry will five years from now. Every developer on the team is a fully AI-native engineer, supported by outstanding internal AI tooling built for every phase of secure development. Developers own their workstreams end-to-end — agents amplify their effectiveness, and peers, security researchers, and external auditors provide rigorous review on every piece of work that ships.

We are looking for a Principal Solana Developer to set the technical direction for our work on the SVM. This is not a seat on an existing Solana team: you are the person who defines what OpenZeppelin's Solana practice looks like, in the open and under your own name, so your reputation compounds with ours.

The engagement

Your first focus is our confidential computing track on Solana: porting onchain fully homomorphic encryption primitives to the SVM runtime, designing the confidential token standard and the SDK patterns on top of it, and building the developer abstractions that make it usable. It runs into 2027, it is public, and it is coordinated directly with the Solana Foundation. The open design questions are yours to own: access control list storage cost, program upgradability and governance, and how to express confidential DeFi flows idiomatically on Solana rather than transliterating them from EVM.

Beyond that engagement, you are the SVM technical lead across our portfolio: shaping how we scope and staff Solana audits, contributing to our open source libraries and tooling, and giving the security research team the depth they need when a program lands on their desk.

Within this, you will:

• Lead our Solana workstreams end to end, from architecture and implementation through audit preparation, deployment and post launch hardening. You make the calls, and you bring others with you.

• Build production grade programs and libraries where security is the primary constraint, not an afterthought. Most of your code will be reviewed by world class auditors.

• Own the hard design questions of a young ecosystem: storage and compute cost models, upgradability and governance, and idiomatic patterns for primitives with no Solana precedent yet.

• Run client facing roadmap and design discussions independently. You are the technical voice in the room, and the person a client's own engineers want to argue with.

• Raise the level of everyone around you: review the team's Solana work, set the standards it is held to, and shorten the ramp for the people coming in behind you.

• Represent OpenZeppelin in the ecosystem: engage with the Solana Foundation, core teams and standards discussions, publish the work, and contribute to our open source libraries and tooling.

• Use AI as a core daily tool: build agents, skills and workflows that compound the team's leverage, apply it directly to security work, and share what works back to the team.

• Collaborate with our blockchain security researchers on cross team research and protocol level threat analysis.

You have

• 3+ years building on Solana in production . Programs you shipped, that other people depend on. You can point at them.

• Demonstrated ability to lead the work. You have owned the architecture and delivery of a multi quarter workstream, made the consequential technical calls, and carried them through review, disagreement and shipping. Leading here means owning technical direction and being the person others align to, not managing headcount.

• Deep SVM fluency. The account model, program derived addresses, cross program invocation, compute budgeting, rent and account lifecycle, versioned transactions and address lookup tables, and program upgradability along with its governance implications. You reason about Solana's constraints natively, not by analogy to the EVM.

• Anchor and beneath it. Y ou are productive in Anchor and equally comfortable working directly against the runtime when the situation calls for it. You know what each choice costs.

• A security first mindset. This is non negotiable. You think adversarially about every line of code you write, and you have demonstrable experience auditing, breaking or hardening production systems.

• An AI native workflow. Claude Code, Cursor or equivalent is your daily driver. You have measurable productivity gains to show for it, clear opinions on how to use these tools well, and you have shipped at least one non trivial AI powered tool, agent or automation pipeline in production, using the Anthropic SDK, MCP, custom evals or comparable.

• Fluency in client facing communication (English). You can run a roadmap call, de

Tailor your resume for this Openzeppelin role before you apply.

Tailor my resume for this job

Similar jobs

More like this: Security & Cybersecurity Jobs · Remote Security & Cybersecurity Jobs · More jobs at Openzeppelin · Browse all jobs

Free ATS checker · How to Autofill Greenhouse Job Applications (Without Sending Junk)