Skip to content

ANNOUNCED SALE · SECURITY · OpenZeppelin

Blockchain Security Researcher

A researcher on the services side of the firm S&P Global has agreed to buy. The work is other people's protocols. The week you join may be the week the owner changes.

You are deciding whether to join a crypto-native security firm in the weeks after it agreed to become a business unit of a ratings company, price undisclosed.

Blockchain Lab analysis, for a candidate deciding whether to apply. We are not the employer. Compensation on this posting: Not disclosed.

Listing age

7 days

Equity

Private. Illiquid.

Sale price

Not disclosed

Where

Remote - Worldwide

Status
Open on the employer board — checked 2026-10-06
Board updated
2026-09-29 · 7 days before this check
Location
Remote - Worldwide
Remote eligibility
Remote - Worldwide
Employment
Not disclosed
Compensation
Not disclosed
Experience, as stored
Security research. Compensation is not in the public feed.
Original post date
Not disclosed

Apply on the employer siteThe companyPractice project

This seat

Blockchain Lab analysis

Security research and review, as the posting describes Security Services. Not sales.

It does not own the Contracts repository, and it should not own a rating decision. If the interview starts blending those, that is the conflict question, live.

The announcement on 17 September 2026 is the context your peers will not all have read. Brener stays, reports to the president of S&P Global Ratings, price undisclosed, library stays open. Your seat is the services business, which is what a ratings company knows how to invoice.

The posting says Remote - Worldwide. That is the employer's phrase. Tax, entity, and sanction screening still exist. Ask which employing company can actually hire your country after the deal.

Updated 29 September 2026. Very fresh, and posted after the acquisition announcement. Someone still wants researchers. That is a good sign and not a guarantee the plan survives close.

The company you would actually join

Blockchain Lab analysis

Public reporting and the employer’s own releases. Not a relationship with Blockchain Lab. Not a credit opinion.

Founded
2015, in Buenos Aires, as Zeppelin.
Base
Distributed. One posting says Remote - Worldwide. The other says Remote. Those are not the same sentence.
Status
Private, with a merger announced. S&P Global said on 17 September 2026 it had agreed to acquire the company. PitchBook marked the deal as announced, not as a closed integration.
People
PitchBook listed about 140 employees. Demian Brener remains CEO under the announced structure.

OpenZeppelin became infrastructure by giving the library away. Contracts is MIT. The commercial company grew up beside it: reviews, monitoring, and a reputation that let a protocol say a serious firm had read the code. On 17 September 2026 S&P Global announced it had agreed to buy that company, keep the name, and have Brener report into S&P Global Ratings. The stated strategic reason is a code-to-credit stack: ratings and risk language for assets that now live on-chain. S&P has spent 2025 and 2026 on exactly that, including on-chain stablecoin assessments and a led round in Kaiko. OpenZeppelin is the engineering piece of that sentence.

Two facts sit underneath the press release. First, Defender is already dead as a hosted product. If your mental model is 'I will work on Defender', update it. Second, the Solana principal role and the security-researcher role are different businesses inside the same brand. One hardens libraries, and this seat is explicitly Solana, on a franchise the market still hears as Ethereum. The other reviews other people's protocols. A ratings-company parent can love the second more than the first, because reviews look like the business S&P already understands. Ask which P&L you are on after close.

Independence is the professional risk. An audit practice owned by a ratings company will be asked, by clients and by cynics, whether a finding can be soft when a rating relationship is hard. S&P will have an answer. You should decide whether you believe it before you take the seat. The library remaining open source is the part of the announcement that is easiest to verify and the part that least determines your Tuesday.

The Canton seat is a third business inside the same brand. The posting asks for a Daml contracts library and reference implementations — a privacy-preserving DEX, lending, stablecoin settlement — coordinated with Digital Asset and the Canton Foundation. That is not the Ethereum audit book and not the Solana principal role. Ask which of those three P&Ls survives inside a ratings company, and whether Canton is a funded roadmap or a single req.

Founders

Demian Brener

Co-founder and CEO

Founded the firm in Buenos Aires in 2015. Under the 17 September 2026 announcement he stays CEO and reports to Yann Le Pallec, president of S&P Global Ratings. The reporting line is the cultural fact. The logo is not.

Manuel Araoz

Co-founder of the library era

Widely credited with the early contracts work. He is not the operating CEO. Candidates who arrive expecting the 2017 blog culture will not find it. The firm that signs your offer is a services and standards business preparing to sit inside a public ratings company.

What the company sells

Contracts

The MIT-licensed library. The company says it remains open source and on GitHub through the deal. v5.6.1 shipped in February 2026.

Security engagements

Audits and design reviews for protocols and institutions. The announcement cites more than 900 engagements and more than 10,000 vulnerabilities caught before production. Those numbers are the company's.

What is gone

Defender, the hosted relay and monitor, closed on 1 July 2026 after a sunset notice the year before. Replacements are self-hosted and AGPL, not the old SaaS.

Capital

Sale price

Not disclosed

Announced 17 Sep 2026.

Company-stated footprint

$37 trillion transferred

S&P's announcement, attributing the library. Not an audit by us.

Engagements

900+

Same announcement. Company-stated.

Revenue

Not disclosed

Private, and now possibly immaterial to the buyer. That is a clue, not a number.

  1. 2015–2018

    Early venture

    Not reliably public

    Databases list seed and Series A activity, including Fabric, BlueYard, Collaborative Fund, and True Ventures among historical investors. Amounts are paywalled or missing. We do not fill them in.

  2. Mar 2023

    Later-stage VC

    Undisclosed

    PitchBook records a completed later-stage round. No post-money we will quote.

  3. 17 Sep 2026

    Agreement to be acquired

    Undisclosed

    S&P Global said the deal is not expected to be material to its results. That sentence is aimed at S&P shareholders. For you it means the price was not large relative to S&P, not that your unvested equity is safe or worthless. Ask counsel.

What should change your mind

  • Deal not described as closed in every database. Your offer may be pre-close or post-close. The benefits, the option plan, and the employer of record change across that line.
  • Undisclosed price. You cannot value an option against a blank.
  • Services culture inside a public parent. Utilisation, conflicts, and a slower ship cycle are the ordinary result. Sometimes that is what you want.
  • Solana versus the Ethereum brand. A principal seat on Solana can be a growth bet or a rounding error. Get it in writing.

Ask them

  • Has the S&P transaction closed, and who is the employer of record on the offer?
  • What happens to unvested equity, and is there a retention grant?
  • Does Security Services stay independent of Ratings engagements?
  • For Solana: is the library a funded roadmap or a single seat?
  • Worldwide remote, on the researcher posting, means which employment entities and which tax setups?

Sources

If a figure is not in those sources, it is not in this brief on purpose.

How the first months would actually go

Illustrative preparation

Not the employer’s onboarding plan.

  1. Days 1–30: one supervised review. Learn their severity scale before you invent one.
  2. Days 31–60: a finding that changed the client's code, written so a non-author can replay it.
  3. Days 61–90: a note on a class of bug you want the library, not the next client, to make impossible. Hand it to the people who own Contracts. Do not freelance a fork.

A week you can rehearse

  • Review something small in public. Findings, severity, and a fix you could retest.
  • Read the S&P release once. Know what you are walking into without reciting it at them.
  • Prepare one question on independence you are willing to ask a future manager.

What to take into the room

Illustrative preparation

  • Present a real bug you found. Include the test.
  • How do you disagree with a senior reviewer who wants a lower severity?
  • What does an independent review mean if the parent also rates the client?

Proof you can build before you apply

  • The security-review lab. Threat model, one mitigation, retest steps. Label it as your exercise, not as an audit of a live protocol.

Open Security review of a local demo. Review a local demo, write the threat model, and document one mitigation.

Walk away if

  • They cannot say whether your offer is OpenZeppelin or S&P.
  • Utilisation targets are quoted and quality review is not.
  • Worldwide means a contractor agreement in your country with no benefits they will describe.

What the employer actually wrote

Employer stated. OpenZeppelin's Security Services team reviews protocols and institutions. This posting is research, not a sales seat.

  • Review smart contracts for top decentralized applications, blockchain infrastructure and financial institutions before they launch. Find vulnerabilities, prioritize them, and present findings to the client.
  • Drive audits independently from start to finish, with AI as your primary collaborator. When useful, partner with another researcher to attack the code together and pressure-test findings.
  • Partner with client teams during the design phase of new protocols, analyzing architecture, trust assumptions, and operational constraints before any code is written (Design Reviews, Applied Research engagements).
  • Use AI efficiently throughout the audit process, and build skills, agents, and workflows that compound across the team.
  • Conduct open-ended research into cutting-edge blockchain technologies, vulnerability classes, and emerging attack vectors, and contribute findings back to OpenZeppelin's internal knowledge base and to the broader ecosystem.

Source: the employer’s public Greenhouse record, job 4254142003. Open the original. First seen by this desk 2026-10-06. Nothing above the fold is a substitute for that page.

A reading of the work

Blockchain Lab analysis. These lines are a reading of the advertisement. They are not extra hiring requirements.

  • Threat-model the privilege boundary before the bug list.
  • Tie each finding to a concrete control, not a slogan.
  • Show how you would re-test the fix.

Still not disclosed

  • Compensation, unless a figure appears in the header. None of these eighteen postings stated one.
  • Closing date, and the day the role was first published. The board timestamp is an update.
  • Visa sponsorship, on-call, and the employing subsidiary.

Not a recommendation to apply. Not an employer assessment. Figures from public reporting move, and a database is not a filing. How this desk labels evidence. Report a listing.

OpenZeppelin · Remote - Worldwide · pay not disclosed

Apply