Resume Score

Check how well your resume matches this job before you apply.

Sign in to check score

About the role

  • Head of Information Security leading OpenZeppelin’s enterprise security, privacy, IT, and AI governance programs. Securing open-source infrastructure used across onchain finance and digital assets.

Responsibilities

  • Own the strategy, design, and continuous maturation of OpenZeppelin's Information Security Program
  • Manage the team executing the Information Security Program
  • Set strategic direction, multi-year roadmap, and risk posture; deliver department OKRs
  • Own the IT and technology budget and technology procurement
  • Lead secure adoption of AI, including AI governance, AI tool and agentic workflow reviews, and agentic infrastructure security
  • Manage frontier model providers as critical vendors, including security and data-handling diligence, retention and training-use commitments, DPAs, and subprocessor flow-downs
  • Address emerging obligations such as the EU AI Act
  • Own audit, certification, and attestation strategy and execution, including penetration testing, SOC 2 Type 2, and ISO/IEC 27001
  • Run third-party and vendor risk management
  • Represent the security program to customer security teams, regulated financial institutions, and auditors
  • Maintain data maps, data classification, records of processing, and vendor/subprocessor inventory
  • Own privacy compliance with Legal, including GDPR, CCPA/CPRA, DPAs, contractual security commitments, and privacy-by-design reviews
  • Own incident response, including playbooks, tabletop exercises, post-incident reviews, and breach notifications
  • Manage bug bounty programs and partner with development teams on SDLC security
  • Oversee identity and access management, provisioning, onboarding/offboarding, endpoint security, physical security, disaster recovery, business continuity, and backups
  • Use automation and AI-powered workflows to scale IT and security operations

Requirements

  • 10+ years of Security and IT experience
  • 3+ years leading an IT Security and GRC function, not solely IT operations, in a high-growth tech company
  • Demonstrated ownership of security strategy, not just execution
  • Trajectory toward CISO, including end-to-end ownership of a security program
  • Experience presenting to executives or boards
  • Ability to articulate the rationale behind implemented controls
  • Experience securing or governing AI/LLM-enabled products or enterprise AI adoption, including agentic systems and third-party model-provider risk
  • Ability to apply privacy and data-protection laws and practices, including GDPR and CCPA/CPRA, in the AI context
  • 5+ years working in blockchain or FinTech with an enterprise client base, including rigorous third-party security diligence (nice to have)

Benefits

  • Meet your teammates at company gatherings around the world 😎
  • Enjoy the flexibility of fully remote work 🌎
  • Take the time you need with flexible time off 🏝
  • 8 weeks of paid leave for primary caregivers
  • 4 weeks of paid leave for secondary caregivers
  • One-time $3,600 baby bonus 💙
  • Up to $500 in equipment support for a home office 🪑
  • Medical insurance 🏥
  • Learning and development opportunities 🧠
  • Monthly stipend for a preferred co-working space 💻
  • Paid work test (up to 20 hours of paid work)

Job type

Full Time

Experience level

Lead

Salary

Not specified

Degree requirement

No Education Requirement

Tech skills

SDLC

Location requirements

RemoteWorldwide

Report this job

Found something wrong with the page? Please let us know by submitting a report below.