Senior Blockchain Security Developer (Canton)

OpenZeppelin
OpenZeppelin

Software Engineering

Remote

Posted on May 21, 2026

About us

OpenZeppelin is the security standard onchain finance is built on. Founded in 2015, our mission is to accelerate the world's transition to an open financial system, built on open standards and secured by rigorous research.

Our open-source Contract Libraries have facilitated over $35 trillion in onchain value and are used by 10 of the top 10 tokenized money market funds and 9 of the top 10 stablecoins by market cap.

We combine AI-native security tooling with deep research and a decade of audit expertise to support leading institutions and crypto-native teams shaping the next generation of digital assets like DTCC, Fidelity, Coinbase, Uniswap, Aave, the Ethereum Foundation, and many more across the full secure development lifecycle.

Please note: Always refer to OpenZeppelin's official job page for the most accurate information about our open roles, as we have seen multiple third party job sites posting inaccurate information.

The Secure Development team ❤️

OpenZeppelin is the security partner of choice for the most important protocols in Web3. Our Secure Development team sits at the intersection of building and breaking: we design, implement, and harden production-grade libraries and smart contracts for leading projects across EVM, Starknet, Stellar/Soroban, Arbitrum Stylus, Aptos, and beyond, often as an embedded extension of the client's engineering team.

We work the way the rest of the industry will five years from now. Every developer on the team is a fully AI-native engineer, supported by outstanding internal AI tooling built for every phase of secure development. Developers own their workstreams end-to-end — agents amplify their effectiveness, and peers, security researchers, and external auditors provide rigorous review on every piece of work that ships.

The Canton Network engagement

This role joins an active 24-month, multi-million-dollar commitment to build the open-source DeFi foundations of the world's most institutional blockchain. You'll deliver production-ready Reference Implementations (privacy-preserving DEX, lending, cross-chain stablecoin settlement, confidential auction launchpad, and more), the OpenZeppelin Contracts Library for Daml that Canton developers will import, and Canton standards implementation.

Within this, you will:

  • Own features of the OpenZeppelin Contracts Library for Daml end to end, from design through audit: examples include a Timelock, access control, vaults, or token standard support.
  • Design and implement components of the year-1 Reference Implementations: privacy-preserving DEX, lending protocol, cross-chain stablecoin settlement, and confidential auction launchpad.
  • Implement and shepherd the OZ Daml versions of CIP-56, CIP-86, CIP-103, future CIPs. Coordinate with Digital Asset on spec evolution and with ChainSafe on middleware alignment.
  • Present and defend your designs in technical discussions with Digital Asset, the Canton Foundation, and other partners.
  • Work with OpenZeppelin's security researchers on threat models, audit preparation, and fixes for the components you own.
  • Use AI systems as core daily tools for research, design, implementation, testing, and security work. Build agents, skills, and workflows, and share what works with the team.
  • Contribute developer-experience and security feedback upstream into the Canton protocol, Splice, the Daml SDK, and the Splice Wallet Kernel.
  • Research privacy-preserving DeFi, multi-party authorization patterns, and Canton-specific primitives, and share what you learn with the team.

You have

  • Production Daml fluency. You understand templates, choices, controllers/observers/signatories, multi-party authorization, sub-transaction views, and propose/accept patterns as first-class primitives. Running an SV, contributing to Splice internals, governance, or Canton Coin tokenomics.
  • Canton architecture depth. You understand the network, not only the code: the Global Synchronizer and private synchronizers, what each party and synchronizer sees in a transaction, smart contract upgrades, and the token standards (CIP-56, CIP-112).
  • 3+ years of smart contract development in production. This includes hands-on work on Canton or another UTXO-based or privacy-preserving architecture (Cardano, Midnight, Zcash, Aleo, Mina, or similar). You can reason about Canton's privacy boundaries the way an EVM developer reasons about storage slots.
  • Production DeFi experience. You have shipped DeFi primitives such as AMMs, vaults (ERC-4626 or equivalent), lending protocols, or cross-chain settlement, and you understand the security pitfalls of each. You know the standard EVM patterns (access control, token standards, lending pools, DEXs), because many Canton standards reuse them.
  • A security-first mindset. This is non-negotiable. You build secure code by default, you think adversarially about every line you write, and you find vulnerabilities when you review Daml code. We look for a developer with a security mindset, not a security researcher. Published audits, threat models, or disclosures are a plus.
  • An AI-native workflow. Claude Code, Cursor, or equivalent is your daily driver. You know agents, harnesses, and skills, not only autocomplete. You hold AI output to the same standard as a colleague's pull request, and you stay accountable for everything you ship.
  • Fluency in client-facing communication (English)
  • Autonomy and proactivity.

Nice to have

  • Cryptography or financial-engineering background. Privacy-preserving DeFi rewards both.
  • Institutional finance and compliance design experience. Credential gates, multi-party attestation, custody flows, capital-markets microstructure, RWA tokenization, settlement.
  • Experience running an SV, contributing to Splice internals, governance, or Canton Coin tokenomics.
  • Cross-chain interoperability exposure. Production work with at least one major cross-chain messaging protocol (Chainlink CCIP, LayerZero, Wormhole, Axelar, or similar).
  • Library / SDK API design taste. You've built reusable, import-first developer libraries, not just applications. You have opinions on extensibility patterns (hooks, modular components, override points) and on what makes an audited primitive pleasant to consume.
  • Experience applying AI to security work. You've already used AI as a serious instrument in security workflows: audit assistance, vulnerability research, fuzzing, invariant or spec analysis, static-analysis augmentation, or similar.
  • Hands-on experience with non-EVM ecosystems. Starknet, Stellar/Soroban, Arbitrum Stylus, Aptos, Move-based chains.
  • Open-source contributions to widely-used libraries in the smart-contract or AI-tooling space.

Logistics

Our interview process is designed to be fast (we target ~30 days from first call to offer) while still giving both sides a clear "yes." The full process consists of:

  • Recruiter interview (30-45 minutes)
  • Manager interview (60 minutes)
  • Team interview (45 minutes)
  • Leadership Interview (30 minutes)
  • Paid technical work trial

Please let us know if you require any accommodations for the interview process, and we’ll do our best to provide assistance.

Benefits

  • Meet your teammates at company gatherings around the world 😎
  • Enjoy the flexibility of fully remote work 🌎
  • Take the time you need with flexible time off 🏝
  • Grow your family with 8 weeks of paid leave for primary caregivers, 4 weeks for secondary caregivers, and a one-time $3,600 baby bonus 💙
  • Build your ideal home office with up to $500 in equipment support 🪑
  • Stay covered with medical insurance 🏥
  • Keep growing with learning and development opportunities 🧠
  • Get a monthly stipend for your preferred co-working space 💻

At OpenZeppelin, we are an equal opportunity employer and we value different perspectives. We are committed to building a diverse workforce. This includes but is not limited to gender, race, sexual orientation, religion, national origin and other characteristics that make each one of us unique. In this uniqueness, we find the most value. Come join us!

Use of AI as part of the recruiting process

As part of OpenZeppelin’s recruitment process, we may use automated tools, including artificial intelligence, to assist in reviewing applications and assessing candidate qualifications. These tools are used to support our People team by identifying relevant skills and experience, and are not used to make decisions solely by automated means. All hiring decisions involve human review. Any personal data provided as part of your application will be processed in accordance with OpenZeppelin’s Data Privacy Notice.

If you have questions about this recruitment process or would like to request human review of your application, please contact us at talent@openzeppelin.com.