> Markdown version of [/jobs/ext/290578-systems-engineer-iv](https://www.wearedevelopers.com/jobs/ext/290578-systems-engineer-iv). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Systems Engineer IV - **Company:** Sprouts Farmers Market - **Location:** Phoenix, AZ, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Android Software Development, Apple IOS, Apple Mac Systems, Application Lifecycle Management, Systems Engineering, Bash Shell, Mobile Application Software, Python (Programming Language), Windows PowerShell, Program Design Languages, Zero Trust Network Access, Mobile Security, Software Deployment, Microsoft InTune, Information Technology, Deployment Automation, Patch Management, 3-tier Architectures, CIS Benchmarks - **Published:** May 31, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=fe2898cac1eb5b62 ## About the Role Do you have experience in UEM?, Do you have a Bachelor's degree?, * Bachelor's degree in Computer Science, Information Technology, or equivalent professional experience. * 5+ years in endpoint engineering or device management roles, with at least 2 years focused on mobile endpoint management (Android at scale). * Deep proficiency with MDM/MAM platforms: Microsoft Intune (required), Kandji, and/or SOTI. * Hands-on experience with Apple Business Manager (ABM), Android Enterprise and Windows Autopilot enrollment programs. * Strong understanding of Conditional Access, Entra ID (Azure AD) device compliance, and app protection policies. * Proficiency in scripting and automation: PowerShell (required), Bash, and/or Python for endpoint lifecycle automation. * Solid understanding of BYOD, COPE, and COBO program design, legal/privacy considerations, and policy enforcement. * Familiarity with endpoint security frameworks (CIS Benchmarks, NIST, DISA STIGs) and patch management best practices. * Excellent problem-solving, analytical, and written/verbal communication skills. Core Competencies * Mobile-First Mindset: Approaches endpoint strategy with mobile as a primary platform, not an afterthought. * Security Orientation: Integrates security thinking into every aspect of device and application lifecycle management. * Communication: Clearly conveys technical concepts to both technical and non-technical stakeholders; actively listens and collaborates. * Customer Focus: Prioritizes end-user experience and business needs while maintaining security and compliance standards. * Driving for Results: Sets measurable goals, pursues continuous improvement, and delivers outcomes with a sense of urgency. * Positive Approach: Demonstrates a constructive attitude in challenging situations and inspires others with a forward-looking outlook. ## Description Please note this position is based in our Phoenix, AZ Support Office. The Sytems Engineer IV - Endpoint Management leads the strategy, design, deployment, and ongoing management of enterprise mobile and endpoint solutions across Windows, macOS, iOS, and Android platforms. This role is the primary subject matter expert for Mobile Device Management (MDM), Mobile Application Management (MAM), and zero-touch device enrollment programs. You will define BYOD, COPE, and COBO policies, enforce mobile security and compliance posture, and collaborate closely with the security team on zero-trust endpoint strategy. In addition, you will mentor junior engineers and drive continuous improvement across the endpoint lifecycle. Essential Functions: * Design, deploy, and manage enterprise MDM/MAM platforms (Microsoft Intune, Kandji/SOTI) with a primary focus on mobile fleet management across iOS, Android, Windows, and macOS. * Architect and administer zero-touch enrollment programs including Apple Business Manager (ABM/DEP), Android Enterprise (Zero-Touch) and Windows Autopilot. * Implement, and enforce BYOD, COPE, and COBO device policies aligned with corporate security standards and regulatory requirements. * Design and manage mobile app protection policies, app configuration profiles, and conditional access policies via Microsoft Intune and Entra ID. * Collaborate with the security team to enforce zero-trust endpoint principles, including device compliance, identity-based access, and continuous monitoring. * Manage endpoint security controls, patch management, software deployment, and compliance policy frameworks across all device types. * Diagnose and resolve complex technical issues across the endpoint stack (hardware, OS, application, MDM policy) including escalated tier 3 incidents. * Perform root cause analysis on endpoint and mobile incidents and implement corrective and preventive measures. * Create and maintain comprehensive documentation for mobile/endpoint architecture, enrollment procedures, policy configurations, and operational runbooks. * Provide leadership, coaching, and mentoring to junior engineers and support staff; act as a technical escalation point across the endpoint practice. * Evaluate emerging mobile and endpoint technologies, vendors, and industry trends; provide recommendations to leadership., Together, these groups celebrate diversity and empower our team to thrive. The above statements are intended to describe the general nature and level of the work being performed by people assigned to this work. This is not an exhaustive list of all duties, responsibilities, and requirements. Sprouts' management reserves the right to amend and change duties, responsibilities, and requirements to meet business and organizational needs as necessary. Sprouts will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of the Fair Chance in Hiring Ordinance. California Residents: We collect information in accordance with California law, please see here for more information. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [A practical guide to writing secure Dockerfiles](https://www.wearedevelopers.com/videos/109-a-practical-guide-to-writing-secure-dockerfiles) - [Old tools, new tricks](https://www.wearedevelopers.com/videos/1916-old-tools-new-tricks) - [Xcode development redefAIned](https://www.wearedevelopers.com/videos/100195-xcode-development-redefained) - [OPA for the cloud natives](https://www.wearedevelopers.com/videos/713-opa-for-the-cloud-natives) - [MCP doesn’t suck — your agent does](https://www.wearedevelopers.com/videos/100202-mcp-doesn-t-suck-your-agent-does) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer)