Senior Blockchain Security Developer (Canton)

Arbitrum

Canton (OH)

Remote

USD 110,000 - 150,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Company gatherings
Flexible time off
Paid parental leave
Work-from-home equipment stipend
Medical insurance
Learning & Development opportunities

Job summary

Arbitrum is looking for a developer to lead the OpenZeppelin Contracts Library for Daml in the United States. You will develop essential privacy-preserving protocols, lead technical designs, and collaborate with stakeholders like Digital Asset and Canton Foundation.

The ideal candidate has fluency in Daml, experience in UTXO-based developments, and a security-first mindset. This fully remote position offers a flexible working environment and perks such as medical coverage and learning opportunities.

Qualifications

  • Shipped non-trivial Daml in production.
  • Production work in a privacy-preserving architecture.
  • Shipped non-trivial DeFi primitives in production.
  • Auditing or hardening production systems experience.
  • Designed reusable, import-first developer libraries.
  • Production work with major cross-chain messaging protocol.
  • Experience in institutional/compliance design.

Responsibilities

  • Own the development of the OpenZeppelin Contracts Library for Daml.
  • Lead technical design and implementation of Reference Implementations.
  • Run client-facing discussions with key stakeholders.
  • Collaborate with auditors on threat models and audits.
  • Apply AI directly to security work.

Skills

Production Daml fluency
3+ years of experience in UTXO-based protocol development
Security-first mindset
Library / SDK API design taste
Cross-chain interoperability exposure
AI-native workflow
Fluency in client-facing communication

Job description

About us

OpenZeppelin is the security standard onchain finance is built on. Founded in 2015, our mission is to accelerate the world's transition to an open financial system, built on open standards and secured by rigorous research.

Our open‑source Contract Libraries have facilitated over $35 trillion in onchain value and are used by 10 of the top 10 tokenized money market funds and 9 of the top 10 stablecoins by market cap.

We combine AI‑native security tooling with deep research and a decade of audit expertise to support leading institutions and crypto‑native teams shaping the next generation of digital assets like DTCC, Fidelity, Coinbase, Uniswap, Aave, the Ethereum Foundation, and many more across the full secure development lifecycle.

Please note: Always refer to OpenZeppelin's official job page for the most accurate information about our open roles, as we have seen multiple third‑party job sites posting inaccurate information.

The Secure Development team

OpenZeppelin is the security partner of choice for the most important protocols in Web3. Our Secure Development team sits at the intersection of building and breaking: we design, implement, and harden production‑grade libraries and smart contracts for leading projects across EVM, Starknet, Stellar/Soroban, Arbitrum Stylus, Aptos, and beyond, often as an embedded extension of the client's engineering team.

We work the way the rest of the industry will five years from now. Every developer on the team is a fully AI‑native engineer, supported by outstanding internal AI tooling built for every phase of secure development. Developers own their workstreams end‑to‑end – agents amplify their effectiveness, and peers, security researchers, and external auditors provide rigorous review on every piece of work that ships.

The Canton Network engagement

This role joins us at the start of a 24‑month, multi‑million‑dollar commitment to build the open‑source DeFi foundations of the world's most institutional blockchain, approved by the Canton Foundation. The scope:

  • 8 production‑ready Reference Implementations. Privacy‑preserving DEX, lending protocol, cross‑chain stablecoin settlement, confidential auction launchpad, and four more defined in year two. End‑to‑end blueprints that other teams will fork.
  • The OpenZeppelin Contracts Library for Daml. The audited foundation Canton developers will import – vaults, hooks, RBAC, credentials, modular multi‑sig accounts, standardized messaging gateway, DeFi math, staking, vesting, auctions, more. The same role our Solidity library plays today, on Canton.
  • Canton standards implementation. Audited Daml implementations of CIP‑56 (Token Standard), CIP‑86 (ERC‑20 Compatible Interface), CIP‑103 (dApp Standard), and CIP‑104 (Traffic‑Based App Rewards) – designed to interoperate cleanly with the broader Splice ecosystem and with ChainSafe's CIP‑86 middleware.
  • 55 researcher‑weeks of dedicated security capacity. Smart‑contract audits, full‑stack reviews, pen tests – amplified by OpenZeppelin's AI security agent in the workflow. Every release ships with a published audit report.
  • AI‑native developer experience for a new ecosystem. Contracts Wizard, UI Builder, MCP Server, Claude Plugin, AI Skills – all built for Canton, all AI‑native end‑to‑end. You'll help define how AI‑native engineering looks on a non‑EVM stack.

You’ll work alongside Digital Asset, the Canton Foundation, and ChainSafe. The deliverables become the standard others build on. The work is public; the impact is measurable; the partners are the institutions reshaping how capital moves. Canton is your first focus, but you'll keep contributing across the broader Secure Development portfolio as the work demands.

Within this, you will:
  • Own the development of the OpenZeppelin Contracts Library for Daml end‑to‑end: vaults, hooks, RBAC, credentials, messaging gateway, accounts, and more. The audited primitives Canton developers will import.
  • Lead the technical design and implementation of the year‑1 Reference Implementations: privacy‑preserving DEX, lending protocol, cross‑chain stablecoin settlement, and confidential auction launchpad.
  • Implement and shepherd the OZ Daml versions of CIP‑56, CIP‑86, CIP‑103, and CIP‑104. Coordinate with Digital Asset on spec evolution and with ChainSafe on middleware alignment.
  • Run client‑facing roadmap, design, and milestone discussions with Digital Asset, the Canton Foundation, and ChainSafe.
  • Collaborate with OpenZeppelin's auditors and security researchers on threat models, audit prep, and full‑stack reviews for every Reference Implementation.
  • Use AI systems as core daily tools. Extend them: build agents, skills, and workflows that compound the team's leverage on the Canton engagement and beyond.
  • Apply AI directly to security work and share what works back to the team: audit assistance, invariant generation, spec analysis, fuzzing harnesses, custom evals.
  • Contribute developer‑experience and security feedback upstream into the Canton protocol, Splice, the Daml SDK, and the Splice Wallet Kernel.
  • Conduct open‑ended research around privacy‑preserving DeFi, multi‑party authorization patterns, and Canton‑specific primitives; you'll have time to publish and contribute back to OpenZeppelin's body of knowledge.
Location

OpenZeppelin is a fully remote organization, however candidates for this position must be located within UTC‑8 to UTC+3 time zones to be considered.

You have
  • Production Daml fluency. You have shipped non‑trivial Daml in production. You understand templates, choices, controllers/observers/signatories, multi‑party authorization, sub‑transaction views, and propose/accept patterns as first‑class primitives. Running an SV, contributing to Splice internals, governance, or Canton Coin tokenomics.
  • 3+ years of experience in UTXO‑based protocol development. You can reason about Canton's privacy boundaries the way an EVM developer reasons about storage slots. Prior production work in a privacy‑preserving or UTXO‑based architecture (Canton, Cardano, Midnight, Zcash, Aleo, Mina, or similar) is expected.
  • 3+ years of experience on DeFi engineering in production. You have shipped non‑trivial DeFi primitives in production: AMMs, vaults (ERC‑4626 or equivalent), lending protocols, cross‑chain settlement. You understand the security pitfalls of each.
  • A security‑first mindset. This is non‑negotiable. You think adversarially about every line of code you write, and you have demonstrable experience either auditing, breaking, or hardening production systems – published threat models, audit reports, responsible disclosures, or equivalent output.
  • Library / SDK API design taste. You've built reusable, import‑first developer libraries, not just applications. You have opinions on extensibility patterns (hooks, modular components, override points) and on what makes an audited primitive pleasant to consume.
  • Cross‑chain interoperability exposure. Production work with at least one major cross‑chain messaging protocol (Chainlink CCIP, LayerZero, Wormhole, Axelar, or similar).
  • Institutional / compliance design fluency: You can design with credential gates, multi‑party attestation, custody flows, and compliance hooks as native constraints.
  • An AI‑native workflow. Claude Code, Cursor, or equivalent is your daily driver. You have measurable productivity gains to show for it and clear opinions on how to use these tools well. You have shipped at least one non‑trivial AI‑powered tool, agent, or automation pipeline in production using the Anthropic SDK, MCP, custom evals, or comparable.
  • Experience applying AI to security work. You've already used AI as a serious instrument in security workflows: audit assistance, vulnerability research, fuzzing, invariant or spec analysis, static‑analysis augmentation, or similar.
  • Fluency in client‑facing communication (English).
  • Autonomy and proactivity.
Nice to have
  • Cryptography or financial‑engineering background. Privacy‑preserving DeFi rewards both.
  • Institutional finance background. Capital‑markets microstructure, custody, compliance flows, RWA tokenization, settlement.
  • Hands‑on experience with non‑EVM ecosystems. Starknet, Stellar/Soroban, Arbitrum Stylus, Aptos, Move‑based chains.
  • Open‑source contributions to widely‑used libraries in the smart‑contract or AI‑tooling space.
Logistics

Our interview process is designed to be fast (we target ~30 days from first call to offer) while still giving both sides a clear "yes." The full process consists of:

  • Recruiter interview (30-45 minutes)
  • Manager interview (60 minutes)
  • Peer interview (45 minutes)
  • Paid technical work trial

Please let us know if you require any accommodations for the interview process, and we’ll do our best to provide assistance.

Benefits
  • Company in‑person gatherings in different locations around the world
  • Fully remote work
  • Flexible time off
  • Paid parental leave
  • One time work‑from‑home equipment stipend of up to $500 USD
  • Medical insurance coverage
  • Learning & Development opportunities
  • Work with a global team in a fast‑growing industry

At OpenZeppelin, we are an equal opportunity employer and we value different perspectives. We are committed to building a diverse workforce. This includes but is not limited to gender, race, sexual orientation, religion, national origin and other characteristics that make each one of us unique. In this uniqueness, we find the most value. Come join us!

Use of AI as part of the recruiting process

As part of OpenZeppelin’s recruitment process, we may use automated tools, including artificial intelligence, to assist in reviewing applications and assessing candidate qualifications. These tools are used to support our People team by identifying relevant skills and experience, and are not used to make decisions solely by automated means. All hiring decisions involve human review. Any personal data provided as part of your application will be processed in accordance with OpenZeppelin’s Data Privacy Notice.

If you have questions about this recruitment process or would like to request human review of your application, please contact us at talent@openzeppelin.com.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Blockchain Security Developer (Canton)
Lead Blockchain Security Developer (Canton)

OpenZeppelin • United States

Remote
USD 100,000 - 150,000
Company in-person gatherings around the world
Flexible time off
Paid parental leave
+4
Principal Security Engineer (Solana)
Principal Security Engineer (Solana)

OpenZeppelin • Canton (OH)

Hybrid
USD 180,000 - 280,000
Fully remote
Flexible time off
Family leave
+4
Content Marketer
Content Marketer

Framework Ventures • United States

Remote
USD 60,000 - 90,000
Fully remote work
Flexible time off
Paid parental leave
+3
Lead Blockchain Security Engineer – Remote, AI-Driven DeFi
Lead Blockchain Security Engineer – Remote, AI-Driven DeFi

OpenZeppelin • United States

Remote
USD 100,000 - 150,000
Company in-person gatherings around the world
Flexible time off
Paid parental leave
+4
Software Engineer Generalist - Devops
Software Engineer Generalist - Devops

Aztec • New York (NY)

Hybrid
USD 130,000 - 170,000
Flexible, remote‑first culture
Competitive salary + equity/token options
25 days annual leave + bank holidays
+2
Software Engineer Generalist - Devops
Software Engineer Generalist - Devops

Crypto Pro Network • New York (NY)

Hybrid
USD 120,000 - 160,000
Competitive salary
Equity/token options
25 days annual leave
Principal Security Engineer (Solana)
Principal Security Engineer (Solana)

OpenZeppelin • United States

Remote
USD 170,000 - 260,000
Senior Software Engineer - Canton
Senior Software Engineer - Canton

Digital Asset • Buffalo (NY)

On-site
USD 190,000 - 220,000
Health benefits
Flexible working
US pay transparency
Senior QA Engineer - Crypto DeFi & Backend APIs (EMEA)
Senior QA Engineer - Crypto DeFi & Backend APIs (EMEA)

Framework Ventures • United States

Remote
Senior Software Engineer, Developer Platform
Senior Software Engineer, Developer Platform

Cyber Fund • United States

On-site
USD 140,000 - 210,000
Remote‑first global workforce
Annual company offsite
Professional reimbursement program
+4