Systems Engineer III - Endpoint Management
Listed on 2026-09-04
-
IT/Tech
Systems Administrator, Systems Engineer, IT Specialist, Windows Server
Overview
The Systems Engineer III – Endpoint Management is a hands‑on engineering role responsible for the day‑to‑day management, configuration, and continuous improvement of Sprouts’ corporate and retail endpoint fleet across Windows and macOS. Working within a small, high‑impact endpoint team, this engineer builds and maintains device configuration, application deployment, patching, and compliance across Microsoft Intune, Microsoft Configuration Manager (SCCM), Tanium, and Kandji.
This is an execution‑focused engineering role. Endpoint strategy and platform direction are set in partnership with the Systems Engineering Supervisor and senior engineers; this position contributes technical recommendations, owns the build and rollout, and serves as an escalation point for the service desk.
The role reports to our Store Support Office in Phoenix, AZ, with a hybrid work arrangement requiring in‑office presence Tuesday through Thursday.
Overview of Responsibilities- Build, deploy, and maintain device configuration profiles, compliance policies, and security baselines across Windows and macOS using Microsoft Intune and Kandji.
- Administer Microsoft Configuration Manager (SCCM) for the existing store and corporate Windows support and the ongoing migration of those devices to Intune and Windows Autopilot.
- Manage zero‑touch enrollment programs including Windows Autopilot and Apple Business Manager (ABM/DEP), including hardware hash management, enrollment status pages, and vendor drop‑ship coordination.
- Own operating system patching and feature update campaigns using Tanium and Intune update rings, including ring design, pilot validation, phased rollout across time zones, communication, and rollback planning.
- Package, test, and deploy applications and application updates across Windows and macOS using Tanium, Intune, Patch My PC, and Kandji, favoring automated role‑based assignment over manual installation.
- Develop and maintain Power Shell automation for endpoint lifecycle tasks including remediation scripts, reporting, bulk operations, and Microsoft Graph API interactions.
- Configure and maintain endpoint security controls including disk encryption, local administrator management, certificate deployment, and CIS benchmark enforcement in partnership with the Information Security team.
- Support Conditional Access and device compliance policy configuration within Microsoft Entra , ensuring devices meet posture requirements before accessing corporate resources.
- Diagnose and resolve escalated tier 3 endpoint incidents spanning hardware, operating system, application, and management‑policy layers; perform root cause analysis and implement preventive fixes.
- Create and maintain operational documentation including enrollment procedures, policy configurations, deployment runbooks, and knowledge base articles for the service desk.
- Serve as a technical escalation point for the service desk and provide coaching and knowledge transfer to support staff and junior engineers.
- Participate in a rotating on‑call schedule providing first‑line tier 3 support for server and infrastructure issues.
- Support off‑hours deployment windows as required for retail store maintenance across multiple time zones.
- Evaluate new endpoint tooling and capabilities through proof‑of‑concept work and provide recommendations to the Systems Engineering Supervisor and senior engineers.
Required
- Bachelor’s degree in Computer Science, Information Technology, or equivalent professional experience.
- 3+ years in endpoint engineering, systems engineering, or device management roles within an enterprise environment.
- Hands‑on proficiency with Microsoft Intune, including configuration profiles, compliance policies, application deployment, and update rings.
- Working experience with Microsoft Configuration Manager (SCCM/MECM) for software distribution, operating system deployment, or patch management.
- Hands‑on experience with Windows Autopilot enrollment, including hardware hash collection, deployment profiles, and Enrollment Status Page configuration.
- Proficiency in Power Shell for endpoint automation, scripting, and reporting; ability to write and troubleshoot scripts…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).