CS HOMEWORK ·Program Manager (Customer Success), OpenZeppelin
ⓘ Independent job-application page. Not affiliated with, endorsed by, or operated by OpenZeppelin. Public data as of September 2026.

Homework for my application to OpenZeppelin.

How I would run strategic ecosystem accounts from kickoff to renewal, and a working engagement desk that scopes a repo, plans the audit, seeds the RAID log and tests scope changes against a change-order rule.

11
ecosystem libraries and stacks tracked live in the demo
3
public foundation terms ending or amended by Dec 2026
93
published OpenZeppelin audits re-measured to benchmark the estimate
95%+
re-engagement rate, NPS 71 (company figures)
00

Summary

The position

The default contracts library on EVM, ported to 10+ stacks, sold to foundations as an Ecosystem Stack. S&P Global agreed to acquire the company on 17 September 2026.

The PM's lever

Foundation terms are milestone-paid and committee-accepted, and newer ones are partly adoption-gated. Clean governance and a written value case decide the renewal.

The work sample

An engagement desk: scope any repo at a pinned commit, estimate effort, run the readiness gate, seed the RAID log, size a scope change, and read each ecosystem library's pulse.

TakeawayWhy it matters for the role
Renewals are due nowTRON's 12-month term ends September 2026 and Stellar's two-year term ends December 2026. Polkadot's 2025 one-year proposal has run its term.
Adoption is part of the invoiceCanton's grant pays half on adoption: 3 independent integrators by milestone 4, 20 projects by milestone 8. Adoption needs tracking from day one.
Scope control protects the brandAfter the November 2025 Balancer exploit, OpenZeppelin's public statement rested on the audited scope. Frozen commits and change orders are a reputational control.
Turnaround is what gets comparedPublic renewal debates at large DAOs focus on cost, turnaround and parallel delivery. Utilisation and on-time metrics feed the renewal case directly.
The buyer is getting more institutionalDTCC, Fidelity, CACEIS and WisdomTree on the client list, a Technical Risk Assessment service for networks, and an S&P Ratings parent. Reporting has to read well for a CFO and a risk committee.
01

OpenZeppelin in 2026

A library company that sells security services, with a growing institutional book.

AreaWhat is publicRead for Customer Success
OwnershipS&P Global agreed to acquire OpenZeppelin on 17 September 2026. It will run as its own business unit under S&P Global Ratings. Audits, engineering and ecosystem programs continue with the same team.Expect institutional procurement, SOC 2 and ISO 27001 questions in client diligence.
ContractsSolidity v5.7 (July 2026). Libraries for Cairo, Stylus, Soroban, Compact, Move, Daml and TVM. Community Contracts as a staging library.Each port is an account with its own release cadence.
ServicesAudits (every line by at least two researchers, then fix review), Secure Development, ZK practice, operational security, Technical Risk Assessment of networks (May 2026).Delivery spans researchers, engineers and DevRel. The PM keeps them on one plan.
Continuous Security ProgramSubscription with reserved researcher capacity and the AI Auditor on every engagement (May 2026).Recurring revenue, and a natural path from a one-off audit.
ToolingDefender sunset on 1 July 2026. Relayer and Monitor open source in Rust. Contracts Wizard, UI Builder, Contracts MCP, Role Manager.Migration questions from former Defender users may land on CS.
Scale900+ audits, 200+ active customers, 95%+ re-engagement, NPS 71, 140+ people (company figures).The retention bar is already high. The work is keeping it through growth.
02

The ecosystem book, from public records

The Ecosystem Stack bundles a library port, audit researcher-weeks, tooling, a bug bounty, developer enablement and a dedicated technical account manager. Public terms below; the account list is larger.

AccountWhat OpenZeppelin deliversTermWhat CS watches
CantonDaml library, reference implementations, 55 researcher-weeks, bounty, TAM24 months from May 2026, 8 quarterly milestonesAdoption-gated payments. Timeline amended September 2026; milestone 2 falls in November.
StellarStellar library, 40 auditor-weeks, Wizard, RWA Wizard, Relayer and MonitorJanuary 2025 to December 2026Renewal case due this quarter. stellar-contracts is on a release candidate.
TRONTVM port, upgradeable variant, upgrades plugins, settlement contracts, TAM with biweekly syncs12 months to September 2026Term ends this month. Libraries audited July 2026.
PolkadotRuntime templates, pallets, Hub libraries, Wizard2025 one-year proposalNo commits in 90 days on the runtime templates. Confirm 2026 intent.
Arbitrum StylusRust contracts library, SDK auditsSince 2024Last release over a year old, 1 commit in 90 days.
Uniswapv4 security partner, Hooks library (Foundation grant)Since 2024Library release cadence and hooks audit pipeline.
Zama, Midnight, Sui, MidenConfidential contracts (ERC-7984), Compact library, Move library, Guardian2025 to 2026 startsYounger accounts: first renewal narratives get written here.
Solana FoundationConfidential computing trackInto 2027New engagement with a principal engineer hire open.
ZKsync, Linea, USDT0, T-REXContinuous release audits, embedded security, compliance infrastructureOngoingContinuous programs: utilisation and turnaround are the metrics.

Sources in §08. Repo signals from the demo's Ecosystem pulse tab, public GitHub data taken 23 September 2026.

03

Competitive map, renewal lens

At renewal, a foundation compares OpenZeppelin with these firms. The library is the moat; price and turnaround are where the comparison happens.

FirmModelWhere it competes at renewal
Certora + ChainSecurityFormal verification plus boutique auditsPaired bids on DAO security retainers; took Compound's 2026 to 2027 program.
Spearbit / CantinaCurated researcher network and contest marketplaceFlexible capacity and contest pricing. No standard library to anchor an ecosystem.
SherlockContests, private audits, Sherlock AI, coverageBundled coverage appeals to DAOs that want a payout backstop.
Trail of BitsDeep research consultancy and open toolingChain-level and infrastructure reviews for foundations.
Zellic, OtterSecResearch boutiques strong on Rust, Move and SolanaDirect overlap on Sui, Solana and Stellar, where OpenZeppelin's library is newer.
CertiK, Halborn, HackenHigh-volume audits, pen testing, compliance angleLower price points; CertiK's ratings sit near where S&P is heading.
Octane, AlmanaxAI-native continuous scanningSame buyer as the Continuous Security Program, without a human audit brand.
ImmunefiBug bounties; absorbed Code4rena's bounty clients in 2026Post-deploy spend. Usually a partner inside the Ecosystem Stack.

Findings from building the engagement desk

The Engagement Desk reads public GitHub data live in the browser. Building it surfaced these.

FindingEvidenceWhat I would do with it
Small diffs and re-scopes look alike in a commit countMorpho Blue v1.0.0 to main is 374 commits ahead, yet in-scope churn is 19 normalised lines (2.2%). Uniswap Hooks v1.1.0 to v1.2.0 is 236 commits with 1,180 lines of churn and 7 new files (76%).Size change requests on normalised in-scope lines, and write the threshold into the SOW.
Two ecosystem libraries are quietrust-contracts-stylus: 1 commit in 90 days, last release 378 days old. polkadot-runtime-templates: none in 90 days.Raise at the next account review before the client raises it at renewal.
Review backlog on the flagship libraryopenzeppelin-contracts: 140 open PRs, 108 merged in 90 days.Track reviewer capacity against roadmap promises made to ecosystems.
Release candidates sit openstellar-contracts v0.8.0-rc.3 is 99 days old during the renewal window.A GA date plus an audit slot is a concrete item for the renewal packet.
Readiness gaps are visible from outsideFloating or mixed pragmas, TODOs at the frozen commit, thin NatSpec and missing specs all show up in a scan before kickoff.Send the readiness list with the SOW, so fixes land before researcher-weeks start burning.
Scope size predicts audit lengthMeasured at their scope commits, 73 full-scope published OpenZeppelin audits fit days ∝ size0.49 (R² 0.48 on log scale, median error 34%). Doubling scope adds about 40% to the calendar.Quote dates from the benchmark and the range, and show the closest past audits next to the quote.
Review-cost signals are countableAssembly, delegatecall, proxies, cross-chain messaging, oracles, signatures, callbacks and custom math each change effort, and each is a regex away.Give Sales a consistent first estimate and give researchers the RAID risks on day one.

The calendar estimate is benchmarked on 93 published OpenZeppelin audit reports (73 full-scope), each re-measured at its scope commit; the dataset and fit are on the demo's Method tab. Researcher-weeks stay a planning input because reports do not state team size.

04

The JD duties, and my plan for each

JD dutyHow I would do itDetailed in
Own the engagementOne account page per ecosystem: term, milestones, sold vs used researcher-weeks, owners, open RAID items, renewal date. Reviewed weekly.§05
Drive deliveryKickoff from a scan-based brief, frozen commit in the SOW, readiness gate a week before start, draft report, fix review, publication with client sign-off.§05, demo
Administer program governanceRASCI per workstream, one milestone plan, one RAID log, a monthly executive status. Artifacts live in Notion and link to GitHub.§05
Orchestrate technical deliveryRequirements sessions become milestones with exit criteria. Go/no-go written at each stage gate. Repo access and vendor onboarding tracked as dependencies.§05, demo
Coordinate third-party infrastructureBounty platforms, oracle and bridge providers as named dependencies with dates. Commercial questions routed to leadership with options.§05
Dependency mapping and riskA cross-team dependency map per account, a risk and compliance register, and a monthly regulatory-readiness review for institutional clients.§05
Build account intelligenceLibrary pulse, governance forum activity, funding and roadmap per ecosystem, refreshed before each account review.★, demo
Grow the accountRenewal packet built from delivered value; expansion into the Continuous Security Program, new library modules and ecosystem-builder audits.§06
Engage technicallyScope estimates from the code itself: nSLOC, review-cost signals, dependency pins. Enough to talk architecture with a CTO.demo
Operate with rigorWeekly utilisation, allocation and on-time delivery per account. Automations for status reports from GitHub, Notion and HubSpot.§05, §07
Unreasonable hospitalitySame-day replies, no surprises on dates, bad news first with a plan attached.§06
05

Engagement governance model

One set of artifacts per account, with a clear owner each and a fixed cadence.

RASCICS PMResearchersSecure DevSales / GrowthExecClient
SOW scope and frozen commitRCCAIS
Readiness gate (go/no-go)ARCIIS
Audit delivery and findingsSA, RCIIC
Library milestonesACRIIC
Change ordersRCCAIS
Report QA and publicationARICIC
Milestone acceptance packetA, RSSCIC
Renewal narrativeRSSACI
CadenceAudienceContents
Biweekly syncClient engineering, OZ leadsMilestone progress, blockers, RAID changes, next two weeks.
Monthly executive statusClient leadership, OZ execOne page: milestone status, researcher-weeks used, findings resolved, adoption KPIs, decisions needed.
Quarterly milestone acceptanceFoundation committeeDeliverables against exit criteria, links to releases and reports, adoption evidence, next quarter's plan.
Renewal review (T-120 days)Sales, Growth, ExecValue delivered, account health, expansion options, risks to renewal.
Weekly internalDelivery leadsUtilisation, allocation, on-time delivery, stage-gate calls due.
Stage gateExit criteriaEvidence
1. ScopedFrozen commit, file list, effort estimate, change-order rule signedSOW with scope table (demo export)
2. ReadyBuild passes, tests run, spec received, repo access grantedReadiness checklist (demo)
3. ReviewedDraft report, readout call heldReport draft, finding tracker
4. FixedFix review complete, each finding resolved or acknowledgedFinal report
5. PublishedClient approval, report live, milestone acceptedBlog post, acceptance record
06

Renewal and expansion moves with the most leverage

MoveMechanicWhy it works
Renewal packet at T-120 daysReleases shipped, audits delivered, findings fixed, TVL on the library, adoption KPIs, researcher-weeks used against sold. One page plus appendix.Committees vote on evidence. Starting early leaves room for a second draft.
Adoption instrumentation from week oneDependency tracking of the library in public repos, Wizard usage, docs analytics, integrator list kept current.Canton-style adoption gates pay only on counted projects.
Turnaround as a published metricDays from request to kickoff and from kickoff to draft report, reported monthly per account.Turnaround is the most common complaint in public renewal threads.
Parallel delivery on retainersQueue audits in parallel lanes by size, with the estimate from the desk deciding the lane.Answers the "one at a time" concern before it is raised.
Audit to Continuous Security ProgramAfter a clean fix review, propose reserved capacity plus the AI Auditor on every PR.Recurring revenue built on a relationship that is already working.
Ecosystem builder auditsRoute ecosystem teams building on the library into audit slots, with the foundation's subsidy where one exists.Expansion inside the account, and adoption evidence for the foundation.
Institutional readiness packSOC 2 and ISO 27001 evidence, report format and publication policy prepared once for bank diligence.Shortens procurement for regulated clients.
07

First 30 / 60 / 90 days

DAYS 1 to 30
Learn the book
  • Meet each account owner and client lead.
  • One account page per ecosystem: term, milestones, weeks used, RAID.
  • Map every renewal date and adoption KPI.
  • Shadow a kickoff, a readout and a publication.
DAYS 31 to 60
Run the cadence
  • Own biweekly syncs and the monthly status on assigned accounts.
  • Standard SOW scope table and change-order rule.
  • First renewal packet drafted with Sales.
  • Automate the weekly utilisation report.
DAYS 61 to 90
Grow the accounts
  • Milestone acceptance delivered on time.
  • Expansion proposal on at least one account.
  • Turnaround and on-time metrics published internally.
  • Calibrate the scoping estimate on past engagements.
08

Method & sources

Built from the public job posting (2026), OpenZeppelin's site and blog, public grant proposals and governance forums, press releases and public GitHub data, read on 2026-09-23. Company figures are labelled as company figures. The demo is my own tool, built for this application, and reads only public GitHub data. Unsolicited interview homework; happy to walk through any section.

Ownership: S&P Global release · OpenZeppelin post

Canton: proposal · amendment

TRON: Ecosystem Stack proposal · library audit

Stellar: SDF partnership · RWA Wizard

Polkadot: 2025 proposal · Arbitrum: Stylus

Services: audit process · readiness guide · Continuous Security Program

Figures: about us · security stats

Scope: Balancer v2 exploit analysis · Defender: sunset FAQ

Renewal debates: Compound 2025 thread · 2026 to 2027 providers

Competitors: Code4rena wind-down · Zellic V12 · Octane

Demo: oz-cs.leverlabs.workers.dev · Repos: github.com/OpenZeppelin

Independent homework for the OpenZeppelin Program Manager (Customer Success) role · 2026 · edwardtay.com