IT Systems Engineer
Listed on 2026-09-12
-
IT/Tech
Cybersecurity, Systems Engineer, Systems Administrator, IT Support
Ibotta is seeking an IT Systems Engineer focused on endpoint and device management to join our IT team and contribute to our mission to Make Every Purchase Rewarding. Reporting to the Engineering Manager, IT, this engineer owns the day-to-day build, automation, and security posture of our Mac and Windows fleet across Jamf Pro and Microsoft Intune. You will implement and operate the platforms that every Ibotta employee touches daily — provisioning, patching, compliance, and identity-integrated device access — and you will partner across IT, Security, and the business to move manual work into automated workflows.
This position is located in Denver, Colorado as a hybrid position requiring 3 days in office (Tuesday, Wednesday, and Thursday). Candidates must live in the United States.
Not based in Denver? We will offer a relocation bonus to help make your move to the Mile High City a smooth one.
What you will be doingAdminister Jamf Pro (macOS/iOS) and Microsoft Intune (Windows) enrollment, configuration profiles, compliance policies, and OS update cycles
Implement zero-touch provisioning across both platforms (Apple Business Manager, Platform SSO, Windows Autopilot) and support authentication workflows with Security/Identity (Managed Apple IDs, Okta Verify, Windows Hello, hardware MFA keys)
Build and maintain security baselines/hardening configs; remediate findings against internal and CIS/SCUBA benchmarks
Drive the Windows endpoint patch automation program to parity with the existing macOS patch pipeline
Develop and maintain scripts (Bash, Python, Swift, Power Shell) for patch deployment, packaging, self-remediation, extension attributes, and lifecycle automation; convert manual tasks into documented, version-controlled workflows
Maintain infrastructure/automation code in Git with branching standards, PRs, and peer review as the default path to production
Package, deploy, and version third-party applications across the fleet
Own full fleet lifecycle operations, enrollment, provisioning, refreshes, recovery, and secure offboarding, aligned with Jira Assets and asset management frameworks
Serve as Tier 3 escalation for endpoint incidents, performing root-cause analysis and converting findings into permanent fixes; manage endpoint-adjacent services (Paper Cut print/badging, device access control); work Jira Service Management tickets with SLA/documentation discipline
Create knowledge base articles, runbooks, and training for Desktop Support/System Administration to enable delegated MDM tasks at the right tier
Support continuous security monitoring and audit evidence collection; identify gaps and propose efficiency improvements
Embrace and uphold Ibotta's Core Values:
Integrity, Boldness, Ownership, Teamwork, Transparency & A good idea can come from anywhere
4+ years in endpoint engineering, systems administration, or IT operations in a mixed Mac and Windows environment
Bachelor's degree in Computer Science,Information Technology or Information Systems preferred; equivalent experience accepted
Hands-on production experience with both Jamf Pro and Microsoft Intune. Depth in one platform with demonstrated working competence in the other is acceptable
Proficiency in at least one scripting language for device automation (Power Shell, Bash, Python, or Swift), and willingness to work in the others
Working knowledge of an enterprise IdP (Okta preferred; Entra ) and how identity, conditional access, and device compliance interact
Experience with patch management and OS update strategy across a distributed fleet
Experience supporting device provisioning at scale (zero-touch, Autopilot, ABM/DEP)
Kanban/Agile working style; comfort operating in a ticket-driven queue with documentation expectations
G…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).