
IT Security Engineer II
Sprouts Farmers Market
Job description
Overview
Job Description
The Security Engineer II is a mid-level individual contributor responsible for implementing, administering, and maintaining the security controls that protect Sprouts' stores, systems, and data. Working across areas such as email, identity, endpoint, data, cloud, and network security, the role operates assigned security platforms following architectures, policies, and standards established by senior security engineers and architects.
The role executes approved changes, responds to assigned security incidents and requests, performs audit-related security controls, and serves as an escalation point for Security Analysts and the Service Desk. Responsibilities include a mix of recurring operational activities, compliance support, incident response, and project-based implementation work.
Within established procedures, the Security Engineer II independently manages alert triage, remediation of compliance issues, and routine changes or exception requests within approved authority levels.
The role reports to our Store Support Office in Phoenix, AZ, with a hybrid work arrangement requiring in-office presence Tuesday through Thursday. Overview Of Responsibilities
Security Engineering & Implementation
-
Implement and modify enterprise security controls across the network, endpoint, cloud, identity, email, and data protection domains, to designs and standards set by the Security Engineer III and the IT Security Architect.
-
Assess systems and security tooling, including Microsoft Azure workloads, against hardening baselines and CIS benchmarks; determine the remediation required; and implement approved changes.
-
Configure proof-of-concept environments for security technologies under evaluation, run the agreed validation testing, and document capabilities, limitations, and results.
-
Prepare and implement approved security platform changes through the enterprise change-management process, including test plans, rollback procedures, and post-implementation validation.
Security Operations & Threat Management
-
Analyze security alerts and logs across email, endpoint, identity, network, and data protection tooling, including CrowdStrike NG-SIEM, and determine disposition against the documented severity matrix.
-
Handle assigned security incidents and requests in ServiceNow through documented response procedures and approval limits: scope the event, coordinate containment and remediation, capture evidence, and document the outcome. Serve as the escalation point for security incidents and requests raised by the Security Analyst I and the Service Desk, and escalate decisions that fall outside those limits to the Security Engineer III or the Manager.
-
Troubleshoot and restore security tooling, including agents, connectors, log feeds, and data integrations: diagnose failures, remediate coverage gaps, and escalate faults that require a platform change by the owning team.
-
Use and adapt the team's existing PowerShell and Python scripts, saved queries, and scheduled reports for recurring work in this role's scope, with support from senior engineering staff where needed, and identify manual work that would benefit from a durable integration.
Identity, Endpoint & Data Protection
-
Administer identity security controls in Okta and Microsoft Entra ID within approved policy, including SSO and SAML application assignment, SCIM provisioning, MFA enrollment and factor resets, conditional access group assignment, and access request fulfillment.
-
Manage endpoint security agent health, coverage, and compliance across CrowdStrike Falcon, BeyondTrust Endpoint Privilege Management, Microsoft Intune, Kandji, and Tanium: investigate compliance failures, determine remediation, apply approved policy, and assess exception requests against documented criteria.
-
Analyze data loss prevention, email security, and information protection alerts in Microsoft Purview, Proofpoint, and Netskope, act on them within documented response procedures, and approve quarantine release, safe-list, and exception requests within documented approval limits.
-
Manage credential, certificate, key, and secrets records in the enterprise vault; execute scheduled rotation and recovery verification; and conduct privileged, service, and user access reviews on the published schedule, tracking exceptions to closure.
Security Governance, Risk & Compliance
-
Execute recurring security control activities on schedule, including tool health checks, access and configuration reviews, policy audits, and key rotations, and compile the control evidence used in SOX IT general controls, PCI DSS, and NIST CSF reviews.
-
Run scheduled vulnerability assessments using CrowdStrike Falcon Spotlight and related tooling, analyze the findings, determine remediation priority with system owners, and report status and aging findings.
-
Complete vendor, supplier, and third-party security reviews; assess findings against the review criteria; escalate risks that require a mitigation decision; and recommend updates to security policies, standards, procedures, and runbooks based on operational experience.
Security Collaboration & Support
-
Assess changes submitted to the security change-approval group against documented security requirements, approve routine changes within documented approval limits, and escalate those that require a design decision or a policy exception.
-
Implement and maintain the security policy layer of platforms operated by partner teams. For example, Netskope SASE platform operations are owned by IT Infrastructure: submit changes through the owning team's process rather than modifying partner-owned systems directly.
-
Contribute to assigned security projects, delivering scoped work to schedule and reporting progress, risks, and blockers.
-
Deliver security awareness and best-practice education to Team Members and stakeholders.
Participate as a full member of the shared 24/7 on-call rotation, including after-hours, weekend, and holiday response. Each engineer takes one week at a time and the cycle repeats across the team, so the interval depends on team size. On-call responsibility is to act as first responder within documented procedures, escalating to the Security Engineer III or the Manager where an issue falls outside them.
Qualifications
Knowledge Skills & Abilities
-
Bachelor's degree in Information Security, Computer Science, Engineering, Information Systems, or an equivalent combination of education and experience.
-
3+ years of information security or enterprise IT operations experience, or comparable hands-on depth in a closely related role.
-
Hands-on experience operating at least one enterprise security platform in production, such as email security, endpoint protection, identity, or data protection.
-
Working knowledge of system and network security practices, authentication technologies, and common security tooling.
-
Experience working tickets to closure in an enterprise IT service management system, with the documentation discipline an audited environment requires.
-
Ability to analyze a security alert or a system's configuration, determine what the correct state should be, and carry the change through to validated completion.
-
Clear written and verbal communication, including the ability to write a runbook another engineer can follow.
-
Adjacent backgrounds are welcome. Systems administration, network engineering, identity administration, and senior service desk experience all transfer well into this role, and prior experience with Sprouts' specific platforms is preferred rather than required.
Preferred Technical Experience
Experience with one or more of the following, or with a recognized equivalent:
-
Microsoft Azure (IaaS, PaaS, Entra ID, Exchange Online)
-
Active Directory
-
Okta or Microsoft Entra ID
-
Netskope or comparable SASE, secure web gateway, or CASB platforms
-
Proofpoint or another secure email gateway, including SPF, DKIM, and DMARC administration
-
CrowdStrike Falcon
-
BeyondTrust Endpoint Privilege Management, or equivalent privileged access and endpoint privilege management tooling
-
Microsoft Purview
-
AI and large language model security, including application discovery and data-egress controls
-
SIEM and security monitoring platforms
-
Microsoft Intune, Kandji, and Tanium
-
Windows Server administration
-
Windows 10/11 endpoint management
-
ServiceNow (ITSM and SecOps)
-
PowerShell and Python scripting
-
Network security technologies, including firewalls, NAC, and Zero Trust concepts
-
Producing control evidence for SOX IT general controls, PCI DSS, or NIST CSF reviews
-
Retail, grocery, or other multi-site operational environments
Preferred Certifications
-
One professional-level security certification, such as CompTIA Security+, CompTIA CySA+, (ISC)ÂČ SSCP, a GIAC certification, or Microsoft SC-200 or AZ-500
-
A vendor certification on any of the platforms listed above
-
ITIL 4 knowledge
No certification is required for this role.
Core Competencies
-
Communication
-
Customer Focus
-
Driving for Results
-
Positive Approach
Benefits
In addition to a rewarding career, Sprouts offers a comprehensive program to help support you and your family. These programs include:
-
Competitive pay
-
Sick time plan that you can use to support you or your immediate families health
-
Vacation accrual plan
-
Opportunities for career growth
-
15% discount for you and one other family member in your household on all purchases made at Sprouts
-
Flexible schedules
-
Employee Assistance Program (EAP)
-
401(K) Retirement savings plan with a generous company match
-
Company paid life insurance
-
Contests and appreciation events throughout the year full of prizes, food and fun!
Eligibility Requirements May Apply For The Following Benefits
-
Bonus based on company and/or individual performance
-
Affordable benefit coverage, including medical, dental and vision
-
Health Savings Account with company match
-
Pre-tax Flexible Spending Accounts for healthcare and dependent care
-
Company paid short-term disability coverage
-
Paid parental leave for both mothers and fathers
-
Paid holidays
Get Paid Every Day!
Sprouts Farmers Market offers DailyPay - if youâre hired as an eligible employee, youâll be able to transfer the money youâve already earned at no extra cost, and get it the next business day, for free
. We offer DailyPay so you donât have to wait for payday to access the money youâve already worked for. With DailyPay, you can see how much youâve made every day and you can transfer your money any time before payday.
You can learn more by visiting https://www.dailypay.com/partners/sprouts-farmers-market/.
Why Sprouts
Grow with us!
If you have a passion for inspiring people and a flair for fresh food, consider applying for a job at Sprouts! With a focus on customer service, our neighborhood grocery stores offer high-quality, farm fresh produce, natural meats, plenty of scoop-your-own bulk goods and much more in a fun, friendly, old-fashioned farmerâs market setting. Come grow your career in healthy living with a fast-paced, rapidly growing company and teams that pride themselves on empowering others along their journey.
The above statements are intended to describe the general nature and level of the work being performed by people assigned to this work. This is not an exhaustive list of all duties, responsibilities, and requirements. Sproutsâ management reserves the right to amend and change duties, responsibilities, and requirements to meet business and organizational needs as necessary. Sprouts will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of the Fair Chance in Hiring Ordinance. California Residents: We collect information in accordance with California law, please see here for more information.