The Lead Entra ID Engineer will manage Microsoft's Entra ID environment, enforce security standards, automate tasks, and mentor junior engineers. Responsibilities also include implementing identity controls and ensuring compliance with regulations.
Job Description
BAE Systems, Inc. is seeking a Lead Entra ID Engineer to join our Identity Services organization, supporting the Directory Services, Certificate Management, and Privileged Access Management (DCP) team. This strategic role focuses on defining and implementing enterprise-wide standards and best practices for Microsoft Entra ID (formerly Azure AD) while collaborating across various departments and IT functions.
As a Lead Entra ID Engineer, you will be responsible for the governance, engineering, and maintenance of our Entra ID environment. You'll lead initiatives around identity modernization, enforce security and compliance standards, and work closely with stakeholders to implement access controls and authentication mechanisms. This is a high-impact, cross-functional role for someone with deep technical expertise and strong communication skills.
Responsibilities Include:
Required Education, Experience, & Skills
Preferred Education, Experience, & Skills
Pay Information
Full-Time Salary Range: $115779 - $196825
Please note: This range is based on our market pay structures. However, individual salaries are determined by a variety of factors including, but not limited to: business considerations, local market conditions, and internal equity, as well as candidate qualifications, such as skills, education, and experience.
Employee Benefits: At BAE Systems, we support our employees in all aspects of their life, including their health and financial well-being. Regular employees scheduled to work 20+ hours per week are offered: health, dental, and vision insurance; health savings accounts; a 401(k) savings plan; disability coverage; and life and accident insurance. We also have an employee assistance program, a legal plan, and other perks including discounts on things like home, auto, and pet insurance. Our leave programs include paid time off, paid holidays, as well as other types of leave, including paid parental, military, bereavement, and any applicable federal and state sick leave. Employees may participate in the company recognition program to receive monetary or non-monetary recognition awards. Other incentives may be available based on position level and/or job specifics.
About BAE Systems, Inc.
BAE Systems, Inc. is the U.S. subsidiary of BAE Systems plc, an international defense, aerospace and security company which delivers a full range of products and services for air, land and naval forces, as well as advanced electronics, security, information technology solutions and customer support services. Improving the future and protecting lives is an ambitious mission, but it's what we do at BAE Systems. Working here means using your passion and ingenuity where it counts - defending national security with breakthrough technology, superior products, and intelligence solutions. As you develop the latest technology and defend national security, you will continually hone your skills on a team-making a big impact on a global scale. At BAE Systems, you'll find a rewarding career that truly makes a difference.
This position will be posted for at least 5 calendar days. The posting will remain active until the position is filled, or a qualified pool of candidates is identified.
BAE Systems, Inc. is seeking a Lead Entra ID Engineer to join our Identity Services organization, supporting the Directory Services, Certificate Management, and Privileged Access Management (DCP) team. This strategic role focuses on defining and implementing enterprise-wide standards and best practices for Microsoft Entra ID (formerly Azure AD) while collaborating across various departments and IT functions.
As a Lead Entra ID Engineer, you will be responsible for the governance, engineering, and maintenance of our Entra ID environment. You'll lead initiatives around identity modernization, enforce security and compliance standards, and work closely with stakeholders to implement access controls and authentication mechanisms. This is a high-impact, cross-functional role for someone with deep technical expertise and strong communication skills.
Responsibilities Include:
- Lead the design, implementation, and continuous improvement of Entra ID (Azure AD) configurations, including:
- User, group, and role management
- Conditional access policies
- Enterprise Applications
- Authentication methods
- Partner with internal teams to enforce governance and security standards across Identity Services.
- Work with compliance teams to ensure identity systems meet regulatory and audit requirements (e.g., NIST, DFARS, CMMC).
- Automate identity-related tasks using PowerShell and Graph API.
- Document processes, standards, and architecture diagrams (e.g., using Visio).
- Provide input and leadership in strategic planning related to directory services.
- Support integrations with related services such as OpenText IDVault, PAM tools, etc.
- Mentor junior engineers and collaborate across Identity Services teams and external business units.
Required Education, Experience, & Skills
- Bachelor's degree in CS, IT or an Engineering discipline
- 3+ years of hands-on experience managing and engineering Microsoft Entra ID (Azure AD).
- Strong experience with PowerShell scripting and Microsoft Graph API for automation and administrative tasks.
- 3+ years of experience with Active Directory in enterprise, multi-domain environments.
- Solid understanding of Windows Hello for Business, including deployment and policy configuration.
- Knowledge of compliance frameworks such as CMMC, DFARS, and NIST.\
- Experience with ServiceNow for incident/request handling or workflow integration.
- Strong written and verbal communication skills; capable of working with cross-functional teams.
Preferred Education, Experience, & Skills
- Master's degree in CS, IT or an Engineering discipline
- Microsoft Certification in Azure/Entra ID.
- Experience with Splunk for identity log monitoring and alert/report creation
- Experience with Visio for technical documentation, including architecture diagrams and workflows.
- Familiarity with other Identity Services tools (SailPoint, OpenText, Okta, Ping, Secret Server, CyberArk, BeyondTrust, etc.)
Pay Information
Full-Time Salary Range: $115779 - $196825
Please note: This range is based on our market pay structures. However, individual salaries are determined by a variety of factors including, but not limited to: business considerations, local market conditions, and internal equity, as well as candidate qualifications, such as skills, education, and experience.
Employee Benefits: At BAE Systems, we support our employees in all aspects of their life, including their health and financial well-being. Regular employees scheduled to work 20+ hours per week are offered: health, dental, and vision insurance; health savings accounts; a 401(k) savings plan; disability coverage; and life and accident insurance. We also have an employee assistance program, a legal plan, and other perks including discounts on things like home, auto, and pet insurance. Our leave programs include paid time off, paid holidays, as well as other types of leave, including paid parental, military, bereavement, and any applicable federal and state sick leave. Employees may participate in the company recognition program to receive monetary or non-monetary recognition awards. Other incentives may be available based on position level and/or job specifics.
About BAE Systems, Inc.
BAE Systems, Inc. is the U.S. subsidiary of BAE Systems plc, an international defense, aerospace and security company which delivers a full range of products and services for air, land and naval forces, as well as advanced electronics, security, information technology solutions and customer support services. Improving the future and protecting lives is an ambitious mission, but it's what we do at BAE Systems. Working here means using your passion and ingenuity where it counts - defending national security with breakthrough technology, superior products, and intelligence solutions. As you develop the latest technology and defend national security, you will continually hone your skills on a team-making a big impact on a global scale. At BAE Systems, you'll find a rewarding career that truly makes a difference.
This position will be posted for at least 5 calendar days. The posting will remain active until the position is filled, or a qualified pool of candidates is identified.
Top Skills
Active Directory
Azure Ad
Microsoft Entra Id
Microsoft Graph Api
Powershell
Servicenow
Splunk
Visio
Similar Jobs at BAE Systems, Inc.
Aerospace • Hardware • Information Technology • Security • Software • Cybersecurity • Defense
Lead and manage a team supporting OSI applications; ensure application performance, collaboration, and stakeholder satisfaction while providing technical guidance and operational oversight.
Top Skills:
.NetAngularBlazorIisMicrosoft Sql ServerMvcWebapiWindows ServerWinforms
Aerospace • Hardware • Information Technology • Security • Software • Cybersecurity • Defense
The Senior IT Asset Management Analyst will lead software asset management strategies, ensure compliance, optimize usage, and mentor teams while collaborating with cross-functional departments for cost savings and efficiency.
Top Skills:
Power BIServicenowTableau
What you need to know about the Kolkata Tech Scene
When considering the industries shaping India's tech scene, gaming might not immediately come to mind. However, in the last decade, increased internet usage and greater access to mobile devices have catapulted the industry to new heights, with Kolkata-based companies like Virtualinfocom, Red Apple Technologies and Digitoonz, at the forefront, driving the design and animation of new gaming titles for players.