How to apply for Staff Engineer, Identity & Access Management (IAM)

Recursion

About Recursion

Recursion is a biotech company using technology to decode biology. The Information Security team enables this by providing secure technology services. The role is remote in the US and focuses on identity and access management.

About the role

As a Staff Engineer, Identity & Access Management, you will assess and revamp IAM strategy across products, platforms, cloud/on-premise infrastructure, and corporate applications. You will drive IAM implementation as part of a zero-trust security strategy and architect cloud-based identity governance and access management solutions. This role is key to ensuring regulatory compliance and enabling business outcomes.

A typical day

A typical day might involve meeting with cross-functional teams to discuss IAM requirements, designing cloud-based identity governance solutions, and reviewing access controls for compliance. You could also be implementing RBAC/ABAC workflows or defining KPIs to measure IAM effectiveness. The role is remote, so collaboration happens via virtual meetings and documentation.

Who Recursion is looking for

  • Experience assessing and revamping IAM strategies across diverse environments (products, platforms, cloud/on-premise, corporate applications).
  • Hands-on experience architecting and designing cloud-based identity governance, access management, and cloud directory solutions.
  • Proven ability to implement RBAC/ABAC based IAM workflows for onboarding and identity lifecycle management.
  • Familiarity with zero-trust security principles and regulatory standards such as SOX and GxP.

Tips for this application

  • Highlight specific IAM projects where you assessed current state and revamped strategy across multiple environments (cloud, on-prem, corporate apps).
  • Emphasize experience with zero-trust security implementations and how you integrated IAM into broader security architecture.
  • Provide concrete examples of designing and implementing RBAC/ABAC workflows for identity lifecycle management.
  • Show familiarity with regulatory compliance standards like SOX and GxP by mentioning how you ensured IAM solutions met these requirements.
  • Mention experience establishing KPIs, KCIs, and KRIs for IAM control effectiveness and continuous improvement.

What to cover in your cover letter

['Your approach to assessing and revamping IAM strategy across products, platforms, cloud/on-premise infrastructure, and corporate applications.', 'How you have driven IAM implementation as part of a zero-trust security strategy.', 'Specific examples of architecting cloud-based identity governance, access management, and cloud directory solutions.', 'Your experience ensuring regulatory compliance (SOX, GxP) through IAM design and collaboration with cross-functional teams.']

Draft a cover letter

Research before applying

  • Research Recursion's business and how technology is used to decode biology, as mentioned in the job description.
  • Look into Recursion's Information Security team and any public information about their security practices or zero-trust initiatives.
  • Understand the regulatory environment Recursion operates in, particularly SOX and GxP requirements for biotech companies.
  • Check Recursion's tech stack and any public details about their cloud infrastructure and products to tailor your IAM experience.

Likely interview topics

Based on the job description, expect questions about:

  • How would you assess our current IAM state and revamp the strategy across products, platforms, cloud/on-premise infrastructure, and corporate applications?
  • Describe your experience implementing IAM as part of a zero-trust security strategy.
  • Walk us through a time you architected a cloud-based identity governance and access management solution.
  • How have you implemented RBAC/ABAC based IAM workflows for onboarding and ongoing identity lifecycle management?
  • How do you ensure IAM solutions meet regulatory standards like SOX and GxP, and what KPIs, KCIs, and KRIs have you used to measure control effectiveness?
Practise interview questions

Common mistakes to avoid

  • Focusing only on one area of IAM (e.g., only cloud or only on-premise) without showing breadth across products, platforms, and corporate applications.
  • Neglecting to mention zero-trust security or how IAM fits into a broader security architecture.
  • Ignoring regulatory compliance aspects like SOX and GxP, which are explicitly mentioned in the job description.

Deadline

No deadline is listed. Roles without a deadline usually close once the employer has enough candidates, so apply soon if you are interested.