Head of Information Security leading OpenZeppelin’s enterprise security, privacy, IT, and AI governance programs. Securing open-source infrastructure used across onchain finance and digital assets.
Responsibilities
Own the strategy, design, and continuous maturation of OpenZeppelin's Information Security Program
Manage the team executing the Information Security Program
Set strategic direction, multi-year roadmap, and risk posture; deliver department OKRs
Own the IT and technology budget and technology procurement
Lead secure adoption of AI, including AI governance, AI tool and agentic workflow reviews, and agentic infrastructure security
Manage frontier model providers as critical vendors, including security and data-handling diligence, retention and training-use commitments, DPAs, and subprocessor flow-downs
Address emerging obligations such as the EU AI Act
Own audit, certification, and attestation strategy and execution, including penetration testing, SOC 2 Type 2, and ISO/IEC 27001
Run third-party and vendor risk management
Represent the security program to customer security teams, regulated financial institutions, and auditors
Maintain data maps, data classification, records of processing, and vendor/subprocessor inventory
Own privacy compliance with Legal, including GDPR, CCPA/CPRA, DPAs, contractual security commitments, and privacy-by-design reviews
Own incident response, including playbooks, tabletop exercises, post-incident reviews, and breach notifications
Manage bug bounty programs and partner with development teams on SDLC security
Oversee identity and access management, provisioning, onboarding/offboarding, endpoint security, physical security, disaster recovery, business continuity, and backups
Use automation and AI-powered workflows to scale IT and security operations
Requirements
10+ years of Security and IT experience
3+ years leading an IT Security and GRC function, not solely IT operations, in a high-growth tech company
Demonstrated ownership of security strategy, not just execution
Trajectory toward CISO, including end-to-end ownership of a security program
Experience presenting to executives or boards
Ability to articulate the rationale behind implemented controls
Experience securing or governing AI/LLM-enabled products or enterprise AI adoption, including agentic systems and third-party model-provider risk
Ability to apply privacy and data-protection laws and practices, including GDPR and CCPA/CPRA, in the AI context
5+ years working in blockchain or FinTech with an enterprise client base, including rigorous third-party security diligence (nice to have)
Benefits
Meet your teammates at company gatherings around the world 😎
Enjoy the flexibility of fully remote work 🌎
Take the time you need with flexible time off 🏝
8 weeks of paid leave for primary caregivers
4 weeks of paid leave for secondary caregivers
One-time $3,600 baby bonus 💙
Up to $500 in equipment support for a home office 🪑
Medical insurance 🏥
Learning and development opportunities 🧠
Monthly stipend for a preferred co-working space 💻
Red Team Security Engineer evaluating Motive's fleet - management platform and cloud environments. Executing adversary simulations, validating detection coverage, and driving remediation of security issues.
Information Systems Security Manager securing RideCo’s cloud - based on - demand transit platform. Leading compliance, risk management, incident response, and security operations.
Senior Security Specialist securing RBC’s cloud banking environments across AWS, Azure, and Google Cloud. Executing red/purple team exercises and refining offensive security tooling.
Senior Security Specialist operating BloodHound Enterprise for RBC, a Canadian bank. Mapping identity attack paths and prioritizing remediation across cloud, AD, DevOps, and PAM environments.
Staff Security Researcher conducting vulnerability research and penetration testing for GitLab’s AI - powered DevSecOps platform. Developing attack methodologies, tooling, and security improvements.
Principal Security Researcher securing GitLab’s AI - powered DevSecOps platform. Leading vulnerability research, AI attack analysis, penetration testing, and remediation across GitLab’s codebase.
Senior security advisor strengthening Desjardins's security posture across governance, data protection, and fraud prevention. Leading complex strategic initiatives for the Desjardins financial services organization.