Head of IT & Security

Real Work From Anywhere Ltd.

United States

Remote

USD 180,000 - 240,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Fully remote work
Global team collaboration
Flexible time off
Learning & development opportunities
Medical insurance

Job summary

OpenZeppelin is hiring for a senior Information Security leader who will own the strategy, design, and maturation of the company’s Information Security Program. You will manage the team, identify risks before they materialize, and articulate the rationale behind security controls to auditors and enterprise security teams.

You will drive IT and security operations, AI governance, privacy practices, and risk management while aligning with regulatory requirements and industry standards.

Qualifications

  • 10+ years of Security and IT experience.
  • Proven track record in building or leading security programs.
  • Experience with AI/LLM security and data privacy practices.

Responsibilities

  • Oversee strategic design and maturation of the Information Security Program.
  • Explain security controls to auditors and enterprise teams.
  • Calibrate program risk posture and governance across the company.
  • Lead identity, access management, incident response, and compliance efforts.
  • Manage budget and vendor risk within security and IT domains.

Skills

Security governance
CISO track
AI security
Auditing
Regulatory compliance

Job description

About us

OpenZeppelin is the security standard onchain finance is built on. Founded in 2015, our mission is to accelerate the world's transition to an open financial system, built on open standards and secured by rigorous research.

Our open-source Contract Libraries have facilitated over $35 trillion in onchain value and are used by 10 of the top 10 tokenized money market funds and 9 of the top 10 stablecoins by market cap.

We combine AI-native security tooling with deep research and a decade of audit expertise to support leading institutions and crypto-native teams shaping the next generation of digital assets like DTCC, Fidelity, Coinbase, Uniswap, Aave, the Ethereum Foundation, and many more across the full secure development lifecycle.

Please note: Always refer to OpenZeppelin's official job page for the most accurate information about our open roles, as we have seen multiple third party job sites posting inaccurate information.

The IT & Security Team

The Information Security function operates independently under our Legal team and owns everything that keeps the OpenZeppelin organization secure. That means managing our Security, Privacy & IT Program end-to-end: our SOC 2 and ISO 27001 posture, vendor and privacy risk, incident response, our bug bounty programs, and the identity, endpoint, and access systems the whole company depends on. It is also the team our customers meet during security diligence. As our enterprise relationships deepen, increasingly with banks and other regulated institutions, our own program must be as credible as the security we deliver to customers.

Today that program is established and audit-ready. The next chapter is turning it into an enterprise-grade security function that stands up to the scrutiny of the most demanding enterprise customers, partners, and regulators, while safely accelerating our adoption of AI across the company.

What you'll be doing

You will own the strategy, design, and continuous maturation of OpenZeppelin's Information Security Program, and be accountable for managing the team executing it. You can issue-spot security and privacy risks before they materialize, explain the principles behind security and compliance controls to auditors and enterprise security teams, and calibrate our security program proportionate to risk.

  • IT and infrastructure: Oversee identity and access management, provisioning and onboarding/offboarding, end-user security (MDM, endpoint protection, security training), physical security, disaster recovery, business continuity, and data backup, using automation and AI-powered workflows to make IT and security operations scale faster than headcount.
  • Strategy, governance and budget: Set the strategic direction, multi-year roadmap, and risk posture of the Information Security Program; deliver on department OKRs; and own the IT and technology budget, with ultimate responsibility for technology procurement.
  • AI security and governance: Own the secure adoption of AI across the company: evolve our AI governance framework, review and approve AI tools and agentic workflows, and secure our agentic infrastructure (identity, least-privilege tool and data access, secrets handling, monitoring, auditability). Manage frontier model providers as critical vendors, covering security and data-handling diligence, retention and training-use commitments, DPAs and subprocessor flow-downs. Meet emerging obligations such as the EU AI Act, so we can make transparent, defensible commitments to enterprise customers about how our products and internal AI usage handle their data.
  • Compliance, audit and enterprise trust: Own our audit, certification, and attestation strategy and execution (penetration testing, SOC 2 Type 2, ISO/IEC 27001, successor frameworks) alongside internal security audits; run a third-party and vendor risk management program; and serve as the external face of our security program with customer security teams, regulated financial institutions, and auditors.
  • Privacy and data governance: Maintain a comprehensive data map of how data flows into, through, and out of the organization, including flows to model providers and through agentic workflows, with data classification, records of processing, and a vendor/subprocessor inventory. Own privacy compliance in partnership with Legal: GDPR, CCPA/CPRA, DPAs and contractual security commitments, and privacy-by-design reviews of new products and features.
  • Security operations and incident response: Own the incident response program end-to-end, including playbooks, tabletop exercises, post-incident reviews, and breach-notification obligations in partnership with Legal. Manage our bug bounty programs, and partner with development teams to embed security best practices in the SDLC and our software offerings.
You have
  • 10+ years of Security and IT experience, including 3+ years leading a IT Security and GRC function (not solely IT operations) in a high-growth tech company, with demonstrated ownership of strategy, not just execution.
  • A demonstrated trajectory toward CISO: you have owned a security program end-to-end, presented to executives or boards, and can articulate the "why" behind every control you have implemented.
  • Experience securing or governing AI/LLM-enabled products or enterprise AI adoption including agentic systems and third‑party model‑provider risk, with an ability to apply privacy and data‑protection laws and practices (e.g., GDPR, CCPA/CPRA) in the AI context.
Nice to have
  • 5+ years working in blockchain or a FinTech with an enterprise client base (e.g., financial services), including navigating rigorous third‑party security diligence.
Logistics:

Our interview process takes place on Google Meet or Zoom and tends to consist of the following stages:

  • Recruiter Call (30 minutes)
  • Hiring Manager Call (30 minutes)
  • Team Interview (30 minutes)
  • Leadership Interview (30 minutes)
  • Paid work test (up to 20 hours of paid work)
  • Reference checks
Benefits
  • Meet your teammates at company gatherings around the world
  • Enjoy the flexibility of fully remote work
  • Take the time you need with flexible time off
  • Grow your family with 8 weeks of paid leave for primary caregivers, 4 weeks for secondary caregivers, and a one-time $3,600 baby bonus
  • Build your ideal home office with up to $500 in equipment support
  • Stay covered with medical insurance
  • Keep growing with learning and development opportunities
  • Get a monthly stipend for your preferred co-working space

At OpenZeppelin, we are an equal opportunity employer and we value different perspectives. We are committed to building a diverse workforce. This includes but is not limited to gender, race, sexual orientation, religion, national origin and other characteristics that make each one of us unique. In this uniqueness, we find the most value. Come join us!

Use of AI as part of the recruiting process

As part of OpenZeppelin’s recruitment process, we may use automated tools, including artificial intelligence, to assist in reviewing applications and assessing candidate qualifications. These tools are used to support our People team by identifying relevant skills and experience, and are not used to make decisions solely by automated means. All hiring decisions involve human review. Any personal data provided as part of your application will be processed in accordance with OpenZeppelin’s Data Privacy Notice.

If you have questions about this recruitment process or would like to request human review of your application, please contact us at talent@openzeppelin.com.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Principal Security Engineer (Solana)
Principal Security Engineer (Solana)

OpenZeppelin • Canton (OH)

On-site
USD 180,000 - 280,000
Fully remote
Flexible time off
Family leave
+4
Lead Blockchain Security Developer (Canton)
Lead Blockchain Security Developer (Canton)

OpenZeppelin • United States

On-site
USD 100,000 - 150,000
Company in-person gatherings around the world
Flexible time off
Paid parental leave
+4
Chief Information Security & AI Governance Leader
Chief Information Security & AI Governance Leader

Real Work From Anywhere Ltd. • United States

Remote
USD 180,000 - 240,000
Fully remote work
Global team collaboration
Flexible time off
+2
Head of Information Security & AI Governance
Head of Information Security & AI Governance

Remotedxb • United States

Remote
USD 180,000 - 300,000
Fully remote work flexibility
Flexible time off
Caregiver leave
+4
Partner 20, Staff Security Engineer, AI & Security Platform
Partner 20, Staff Security Engineer, AI & Security Platform

Andreessen Horowitz • San Francisco (CA)

On-site
USD 243,000 - 284,000
Health insurance
Dental insurance
Vision insurance
+5
Senior Staff Software Security Engineer
Senior Staff Software Security Engineer

United States Digital Space LLC • Bellevue (CA)

On-site
USD 247,000 - 290,000
Health insurance
Equity
401(k) matching
+2
Partner 20, Staff Engineer, Enterprise Security
Partner 20, Staff Engineer, Enterprise Security

Theblockchainassociation • San Francisco (CA)

Hybrid
USD 243,000 - 284,000
Health insurance
Dental insurance
Vision insurance
+6
Partner 20, Staff Engineer, Enterprise Security
Partner 20, Staff Engineer, Enterprise Security

A16z • San Francisco (CA)

On-site
USD 243,000 - 284,000
Health insurance
Dental insurance
Vision insurance
+7
Principal Software Engineer, Infrastructure Security
Principal Software Engineer, Infrastructure Security

OpenAI • New York (NY)

On-site
USD 277,600 - 490,000
Medical, dental, and vision insurance
401(k) retirement plan with employer match
Paid parental leave
+5
Partner 20, Staff Security Engineer, AI & Security Platform
Partner 20, Staff Security Engineer, AI & Security Platform

Andreessen Horowitz (a16z) • San Francisco (CA), Northern (KY)

On-site
USD 243,000 - 284,000
Carry program
Health insurance
Dental insurance
+4