Blockchain Security Researcher
Job description
About the role
OpenZeppelin is the security standard onchain finance is built on, and this role owns the responsibility of advancing AI-native security research to protect the world's leading web3 protocols and financial institutions. You own the full lifecycle of security research, from discovering deep architectural vulnerabilities to co-creating secure smart contract designs with engineering teams before any code is written. You own the mandate to use AI as a primary collaborator, pushing the boundaries of audit coverage and ensuring findings are translated into actionable risk reports for clients at the highest level. This position owns the challenge of independently driving audits from start to finish, applying creative problem-solving to novel attack vectors and complex protocol mechanisms. You own the contribution of knowledge back to the community and internal tools, shaping OpenZeppelin's research standards and tooling for the next generation of onchain defenders. This role owns the mission of accelerating a secure transition to an open financial system by ensuring the integrity of the foundational code that moves trillions in value. You own the continuous learning and adaptation required to keep pace with emerging blockchain technologies and evolving cryptographic attack surfaces.
Key facts
What you'll do
Review smart contracts for top decentralized applications, blockchain infrastructure and financial institutions before they launch, finding vulnerabilities, prioritizing them, and presenting findings to the client.
Drive audits independently from start to finish, with AI as your primary collaborator, and partner with another researcher to attack the code together and pressure-test findings when useful.
Partner with client teams during the design phase of new protocols, analyzing architecture, trust assumptions, and operational constraints before any code is written through Design Reviews and Applied Research engagements.
Design and help develop smart contracts as part of co-creative engagements with protocol teams, where research, design, specification, and implementation happen together in a tightly integrated workflow.
Use AI efficiently throughout the audit process, building skills, agents, and workflows that compound across the team and consistently expand audit depth and accuracy.
Conduct open-ended research into cutting-edge blockchain technologies, vulnerability classes, and emerging attack vectors, and contribute findings back to OpenZeppelin's internal knowledge base and to the broader ecosystem.
Analyze trust assumptions and economic invariants within cryptoeconomic systems, evaluating game-theoretic security and potential misalignments in protocol incentives.
Perform manual and automated code analysis across multiple programming languages and virtual machines, including EVM bytecode, Move, Cairo, and other smart contract execution environments.
Validate the correctness of cryptographic implementations and cross-chain bridge protocols, ensuring that security properties hold under real-world network conditions and adversary models.
Collaborate with product and engineering teams to integrate security best practices into development lifecycles, defining standards and guardrails that prevent vulnerabilities from reaching production.
Requirements
Hands-on and practical experience in one or more of the following: software development, cybersecurity, applied mathematics, distributed systems, cryptography, cryptoeconomics or game theory, or DeFi mechanisms.
Experience designing and developing smart contracts, not only auditing them, demonstrating a deep understanding of implementation constraints and secure coding patterns.
Strong working knowledge of Solidity and the broader Ethereum / EVM ecosystem, including common libraries, frameworks, smart contract patterns, and upgrade mechanics.
Modern AI tooling is central to how you work, not a novelty; you use it daily to expand audit coverage, reason about complex systems, and produce high-quality outputs faster while evaluating AI-generated code with a critical eye.
Comfort building and extending your own tooling, including skills, agents, prompts, scripts, or full workflows, that the rest of the team can adopt and build upon to scale research impact.
An advanced English level and strong communication skills, both oral and written, enabling clear articulation of complex technical risks to diverse stakeholders.
Ability to work asynchronously in a fully remote environment, managing independent ownership of tasks while coordinating effectively with global teams and clients.
Willingness to travel to client sites and engage with research communities when required, supporting in-depth engagements and knowledge transfer on critical security initiatives.
Nice to have
Experience with non-EVM ecosystems and languages, such as Canton, Move (Sui, Aptos), Golang (Cosmos SDK), Cairo (Starknet), Rust-based blockchains (Solana, Stellar), or ZK circuits and cryptography-heavy systems.
Practical notes
This position is for a future opening.
Please note always refer to OpenZeppelin's official job page for the most accurate information about our open roles, as we have seen multiple third party job sites posting inaccurate information.