Lead Entra ID / Azure AD Engineer

New Today

BAE Systems, Inc. is seeking a Lead Entra ID Engineer to join our Identity Services organization, supporting the Directory Services, Certificate Management, and Privileged Access Management (DCP) team. This strategic role focuses on defining and implementing enterprise-wide standards and best practices for Microsoft Entra ID (formerly Azure AD) while collaborating across various departments and IT functions.
As a Lead Entra ID Engineer, you will be responsible for the governance, engineering, and maintenance of our Entra ID environment. You ll lead initiatives around identity modernization, enforce security and compliance standards, and work closely with stakeholders to implement access controls and authentication mechanisms. This is a high-impact, cross-functional role for someone with deep technical expertise and strong communication skills.
Responsibilities Include:
Lead the design, implementation, and continuous improvement of Entra ID (Azure AD) configurations, including:
User, group, and role management
Conditional access policies
Enterprise Applications
Authentication methods
Partner with internal teams to enforce governance and security standards across Identity Services.
Work with compliance teams to ensure identity systems meet regulatory and audit requirements (e.g., NIST, DFARS, CMMC).
Automate identity-related tasks usingPowerShellandGraph API.
Document processes, standards, and architecture diagrams (e.g., using Visio).
Provide input and leadership in strategic planning related to directory services.
Support integrations with related services such as OpenText IDVault, PAM tools, etc.
Mentor junior engineers and collaborate across Identity Services teams and external business units.
Required Education, Experience, & Skills
Required Education:
Bachelor's degree in CS, IT or an Engineering discipline
Required Skills & Experience:
3 years of hands-on experience managing and engineeringMicrosoft Entra ID (Azure AD).
Strong experience withPowerShell scriptingand Microsoft Graph API for automation and administrative tasks.
3 years of experience withActive Directoryin enterprise, multi-domain environments.
Solid understanding ofWindows Hello for Business, including deployment and policy configuration.
Knowledge ofcompliance frameworkssuch as CMMC, DFARS, and NIST.
Experience withServiceNowfor incident/request handling or workflow integration.
Strong written and verbal communication skills; capable of working with cross-functional teams.
Preferred Education, Experience, & Skills
Preffered Education:
Master's degree in CS, IT or an Engineering discipline
Preferred Qualifications:
Microsoft Certificationin Azure/Entra ID.
Experience withSplunkfor identity log monitoring and alert/report creation.
Experience withVisiofor technical documentation, including architecture diagrams and workflows.
Familiarity withother Identity Services tools (SailPoint, OpenText, Okta, Ping, Secret Server, CyberArk, BeyondTrust, etc.)
Pay Information
Full-Time Salary Range: $115779 - $196825
Please note: This range is based on our market pay structures. However, individual salaries are determined by a variety of factors including, but not limited to: business considerations, local market conditions, and internal equity, as well as candidate qualifications, such as skills, education, and experience.
Employee Benefits: At BAE Systems, we support our employees in all aspects of their life, including their health and financial well-being. Regular employees scheduled to work 20 hours per week are offered: health, dental, and vision insurance; health savings accounts; a 401(k) savings plan; disability coverage; and life and accident insurance. We also have an employee assistance program, a legal plan, and other perks including discounts on things like home, auto, and pet insurance. Our leave programs include paid time off, paid holidays, as well as other types of leave, including paid parental, military, bereavement, and any applicable federal and state sick leave. Employees may participate in the company recognition program to receive monetary or non-monetary recognition awards. Other incentives may be available based on position level and/or job specifics.
Lead Entra ID / Azure AD Engineer
115215BR
EEO Career Site Equal Opportunity Employer. Minorities . females . veterans . individuals with disabilities . sexual orientation . gender identity . gender expression
Location:
Falls Church, VA, United States
Job Type:
FullTime
Category:
Computer And Mathematical Occupations

We found some similar jobs based on your search