Principal Security Engineer
Job description
About the role
OpenZeppelin is the security standard onchain finance is built on, and this role places you at the center of that mission where you will define and enforce the security architecture for Solana-based systems. You will own the full lifecycle of secure development, from initial design and threat modeling through implementation, audit preparation, and post-deployment hardening of production-grade solutions. Your work will directly shape how OpenZeppelin builds on the Solana Virtual Machine, influencing not only internal libraries but also the broader ecosystem of protocols and developers. You will act as the primary technical authority on Solana security, setting the standards and direction that the industry follows for years to come. This position requires deep collaboration with researchers, auditors, and client engineering teams to ensure every line of code meets the highest bar for safety and reliability. You will leverage advanced AI-native tooling to scale secure development practices while maintaining rigorous human oversight and expert judgment.
Key facts
What you'll do
Define the end-to-end architecture for confidential computing primitives on Solana, including porting fully homomorphic encryption workflows to the SVM runtime and designing confidential token standards.
Design and implement production-grade programs and libraries where security is the primary constraint, ensuring robust access control, storage cost optimization, and upgradability patterns.
Own the hard systems design questions for a young ecosystem, including storage and compute cost models, governance frameworks, and idiomatic patterns for Solana-specific primitives.
Lead client-facing roadmap and design discussions, serving as the definitive technical voice in critical meetings and defending architectural decisions with clarity and evidence.
Raise the level of all engineers around you by performing deep code reviews, establishing security standards, and accelerating the onboarding of new team members.
Represent OpenZeppelin in the broader Solana ecosystem by engaging with the Solana Foundation, core infrastructure teams, and standards bodies to advance secure practices.
Publish technical work and contribute actively to open source libraries, ensuring that OpenZeppelin's research and implementations remain at the forefront of the industry.
Coordinate closely with the security research and audit teams to translate findings into hardened code and to anticipate future threat vectors on Solana.
Leverage internal AI-native tooling across the entire development lifecycle, from automated analysis and testing to intelligent review and documentation.
Maintain strict alignment with the confidential computing track objectives, ensuring all deliverables are public, auditable, and coordinated with foundation stakeholders.
Drive the creation of SDK patterns and developer abstractions that make confidential DeFi flows idiomatic on Solana rather than transliterated from EVM models.
Continuously monitor the evolving Solana runtime and ecosystem to identify risks and opportunities for proactive security improvements.
Act as the central point of ownership for Solana workstreams, making final technical calls and ensuring timely, high-quality execution against demanding schedules.
Build long-term trust with clients and partners by demonstrating deep expertise, transparency, and consistent delivery of secure, scalable solutions.
Requirements
Candidates must have extensive experience developing secure systems on Solana, with a proven track record of delivering complex programs and libraries that withstand rigorous audit and production scrutiny.
You must be deeply familiar with Solana runtime constraints, including program size limits, instruction costs, and account lifecycle management, and able to design solutions that respect these boundaries.
You should have hands-on experience with confidential computing concepts and fully homomorphic encryption, including practical knowledge of how these techniques can be implemented in onchain environments.
Strong expertise in Rust is required, with the ability to write high-performance, memory-safe code that meets the strict correctness standards expected by security-critical applications.
You must have experience working with token standards and DeFi primitives on Solana, including associated security patterns and economic incentive considerations.
Demonstrated ability to operate independently in a high-ambiguity environment, defining problems as well as solutions while balancing trade-offs between security, cost, and usability.
Excellent written and verbal communication skills are essential, as you will regularly present technical reasoning to both expert and non-expert audiences.
You must be comfortable working in a fast-paced, rapidly evolving ecosystem where priorities can shift based on research findings and protocol upgrades.
Nice to have
Experience contributing to open source security-critical Rust projects and a history of public contributions to blockchain infrastructure.
Deep involvement in Solana ecosystem standards discussions, governance processes, and protocol upgrades.
Familiarity with AI-assisted development workflows and prompt engineering for secure coding assistance.
Practical notes
This is a confidential long-term engagement coordinated directly with the Solana Foundation, with work running into 2027 as part of OpenZeppelin's confidential computing track.
The role is fully remote, and candidates must be able to work independently across global time zones while aligning with Foundation schedules.
No specific travel or visa requirements are outlined at this time, but the position may require occasional collaboration during intensive design and audit cycles.