OpenZeppelin logo
OpenZeppelin·

Principal Security Engineer (Solana) - OpenZeppelin

About us

OpenZeppelin is the security standard onchain finance is built on. Founded in 2015, our mission is to accelerate the world's transition to an open financial system, built on open standards and secured by rigorous research.

Our open-source Contract Libraries have facilitated over $35 trillion in onchain value and are used by 10 of the top 10 tokenized money market funds and 9 of the top 10 stablecoins by market cap.

The Secure Development team ❤️

OpenZeppelin is the security partner of choice for the most important protocols in Web3. Our Secure Development team sits at the intersection of building and breaking: we design, implement, and harden production-grade libraries and smart contracts for leading projects across EVM, Starknet, Stellar/Soroban, Arbitrum Stylus, Aptos, and beyond.

We are looking for a Principal Solana Developer to set the technical direction for our work on the SVM. This is not a seat on an existing Solana team: you are the person who defines what OpenZeppelin's Solana practice looks like, in the open and under your own name.

The engagement

Your first focus is our confidential computing track on Solana: porting onchain fully homomorphic encryption primitives to the SVM runtime, designing the confidential token standard and the SDK patterns on top of it, and building the developer abstractions that make it usable. It runs into 2027, it is public, and it is coordinated directly with the Solana Foundation.

Beyond that engagement, you are the SVM technical lead across our portfolio: shaping how we scope and staff Solana audits, contributing to our open source libraries and tooling, and giving the security research team the depth they need when a program lands on their desk.

Within this, you will:

  • Lead our Solana workstreams end to end, from architecture and implementation through audit preparation, deployment and post launch hardening.
  • Build production grade programs and libraries where security is the primary constraint, not an afterthought.
  • Own the hard design questions of a young ecosystem: storage and compute cost models, upgradability and governance, and idiomatic patterns.
  • Run client facing roadmap and design discussions independently as the technical voice in the room.
  • Raise the level of everyone around you: review the team's Solana work, set standards, and mentor incoming engineers.
  • Represent OpenZeppelin in the ecosystem: engage with the Solana Foundation, core teams, and standards discussions.
  • Use AI as a core daily tool: build agents, skills, and workflows that compound the team's leverage.
  • Collaborate with our blockchain security researchers on cross team research and protocol level threat analysis.

You have

  • 3+ years building on Solana in production. Programs you shipped that other people depend on.
  • Demonstrated ability to lead the work. Owned architecture and delivery of multi-quarter workstreams.
  • Deep SVM fluency. Account model, program derived addresses, cross program invocation, compute budgeting, rent and account lifecycle, versioned transactions, and program upgradability.
  • Contributions to standards. Solana Improvement Documents, SPL and Token 2022 extensions, or the Wallet Standard.
  • Experience working alongside a foundation or core protocol team.
  • Anchor and runtime proficiency. Productive in Anchor and comfortable working directly against the runtime.
  • A security first mindset. Think adversarially about every line of code; experience auditing, breaking, or hardening production systems.
  • An AI native workflow. Daily driver of Claude Code, Cursor, or equivalent, with measurable productivity gains.
  • Fluency in client facing communication (English).
  • Alignment with OpenZeppelin's values.

Nice to have

  • Public standing in the Solana ecosystem
  • Cryptography background (FHE, ZK systems, applied crypto)
  • Compute unit and cost optimization depth
  • Prior audit or security research output
  • Experience applying AI to security work
  • Hands-on experience with other non-EVM ecosystems (Move, Stellar/Soroban, Stylus, Starknet)

Culture

Async-friendly

Open to

Worldwide

Sign in to track applications and earn points.

More roles at OpenZeppelin

Similar remote roles