TopWeb3JobsTopWeb3Jobs
Security & Audit district · Plot CS-A1-07

Head of IT & Security

openzeppelin · Remote (Worldwide) · Full-time
Salary not listed

About the role

OpenZeppelin has been the foundation of onchain security since 2015. The company works with the world's leading crypto institutions—Coinbase, Uniswap, Aave, Ethereum Foundation, Fidelity, and others—to secure digital assets and financial infrastructure. OpenZeppelin's open-source libraries have supported over $35 trillion in onchain value, and the company now combines AI-powered security tools with deep research to help shape the next generation of regulated digital finance.

The IT & Security function operates independently and owns the full spectrum of organizational security: SOC 2 and ISO 27001 compliance, vendor risk management, incident response, identity and access systems, bug bounty programs, and privacy governance. As OpenZeppelin deepens relationships with banks and regulated institutions, the security program itself must meet the same rigor expected of the company's customer offerings.

What you'll do

  • Lead strategy and multi-year roadmap for OpenZeppelin's Information Security Program while managing the team executing it, with accountability for risk posture and departmental OKRs.
  • Oversee identity and access management, endpoint security, disaster recovery, business continuity, and data backup across the organization, leveraging automation and AI workflows to scale operations beyond headcount growth.
  • Build governance frameworks for AI adoption across the company, including review of AI tools and agentic workflows, vendor diligence for frontier model providers, data retention commitments, and compliance with emerging regulations like the EU AI Act.
  • Own the audit, certification, and compliance strategy covering SOC 2 Type 2, ISO/IEC 27001, penetration testing, and vendor risk programs; serve as the security face to enterprise customers, financial institutions, and auditors.
  • Maintain comprehensive data governance including mapping data flows to model providers and agentic systems, managing vendor inventories, and ensuring GDPR, CCPA/CPRA, and contractual privacy commitments are met.
  • Design and execute incident response programs including playbooks, tabletop exercises, and post-incident reviews in partnership with Legal.

What you'll bring

  • 10+ years in security and IT with at least 3 years leading an IT Security and GRC function in a high-growth tech environment, with demonstrated ownership of strategy beyond execution.
  • Proven trajectory toward CISO: you've owned a security program end-to-end, presented to executives or boards, and can explain the reasoning behind every control you've implemented.
  • Hands-on experience securing or governing AI and LLM products, including agentic systems and third-party model provider risk, with ability to apply GDPR, CCPA/CPRA, and privacy practices in AI contexts.

Nice to have

  • 5+ years in blockchain or FinTech serving enterprise clients, including managing rigorous third-party security diligence processes.

What We Offer

  • Remote, worldwide position with full-time employment.
  • Interview process includes recruiter call, hiring manager call, team interview, leadership interview, and a paid work test component (up to 20 hours).

Pay, location & hours

Salary not listed. Fully remote, open to applicants in any country.

About openzeppelin

2 open roles in this building · Company page → · See it on the map

Apply ↗

More roles to explore

Salary not listed
openzeppelin
Apply ↗

☆ Save this job

We'll e-mail you this role so you can come back to it. No account needed.

Report this job

Reports go to the TopWeb3Jobs team. Scam reports are checked first.