Sprouts runs an Azure-first cloud stack-including Databricks, Synapse/Fabric, and Azure Virtual Desktop-alongside store systems, point-of-sale, and payment infrastructure under PCI-DSS. The role ...
Sprouts runs an Azure-first cloud stack-including Databricks, Synapse/Fabric, and Azure Virtual Desktop-alongside store systems, point-of-sale, and payment infrastructure under PCI-DSS. The role ...
Senior IT Security Architect
Phoenix, AZ · On-site
Sprouts runs an Azure-first cloud stack-including Databricks, Synapse/Fabric, and Azure Virtual Desktop-alongside store systems, point-of-sale, and payment infrastructure under PCI-DSS. The role ...
Senior IT Security Architect
Phoenix, AZ · On-site
Sprouts runs an Azure-first cloud stack-including Databricks, Synapse/Fabric, and Azure Virtual Desktop-alongside store systems, point-of-sale, and payment infrastructure under PCI-DSS. The role ...
Sprouts runs an Azure-first cloud stack-including Databricks, Synapse/Fabric, and Azure Virtual Desktop-alongside store systems, point-of-sale, and payment infrastructure under PCI-DSS. The role ...
Sprouts runs an Azure-first cloud stack-including Databricks, Synapse/Fabric, and Azure Virtual Desktop-alongside store systems, point-of-sale, and payment infrastructure under PCI-DSS. The role ...
Senior IT Security Architect
Phoenix, AZ · On-site
Sprouts runs an Azure-first cloud stack--including Databricks, Synapse/Fabric, and Azure Virtual Desktop--alongside store systems, point-of-sale, and payment infrastructure under PCI-DSS. The role ...
Senior IT Security Architect
Phoenix, AZ · On-site
Sprouts runs an Azure-first cloud stack--including Databricks, Synapse/Fabric, and Azure Virtual Desktop--alongside store systems, point-of-sale, and payment infrastructure under PCI-DSS. The role ...
Configuration Technician I
Phoenix, AZ · On-site
$17.75 - $19.25/hr
Support Azure Virtual Desktop (AVD) and Vision deployments, including QA, staging, and printer tagging. * Troubleshoot and resolve printer issues during and after deployments, including remote ...
Configuration Technician I
Phoenix, AZ · On-site
$17.75 - $19.25/hr
Support Azure Virtual Desktop (AVD) and Vision deployments, including QA, staging, and printer tagging. * Troubleshoot and resolve printer issues during and after deployments, including remote ...
Configuration Technician I
Phoenix, AZ · On-site
$17.75 - $19.25/hr
Support Azure Virtual Desktop (AVD) and Vision deployments, including QA, staging, and printer tagging. * Troubleshoot and resolve printer issues during and after deployments, including remote ...
Quick apply
Configuration Technician I
Phoenix, AZ · On-site
$17.75 - $19.25/hr
Support Azure Virtual Desktop (AVD) and Vision deployments, including QA, staging, and printer tagging. * Troubleshoot and resolve printer issues during and after deployments, including remote ...
Configuration Technician I
$17.50 - $18.75/hr
Support Azure Virtual Desktop (AVD) and Vision deployments, including QA, staging, and printer tagging. * Troubleshoot and resolve printer issues during and after deployments, including remote ...
Configuration Technician I
$17.50 - $18.75/hr
Support Azure Virtual Desktop (AVD) and Vision deployments, including QA, staging, and printer tagging. * Troubleshoot and resolve printer issues during and after deployments, including remote ...
Senior Architect - M365
Phoenix, AZ · On-site +1
Experienced in Windows administration, Virtual Desktop Infrastructure (VDI) solutions including Citrix and Azure Virtual Desktop (AVD), Mac OS and Jamf as well as mobile device management.
Senior Architect - M365
Phoenix, AZ · On-site +1
Experienced in Windows administration, Virtual Desktop Infrastructure (VDI) solutions including Citrix and Azure Virtual Desktop (AVD), Mac OS and Jamf as well as mobile device management.
Senior Architect - M365
Phoenix, AZ · On-site +1
Experienced in Windows administration, Virtual Desktop Infrastructure (VDI) solutions including Citrix and Azure Virtual Desktop (AVD), Mac OS and Jamf as well as mobile device management.
Senior Architect - M365
Phoenix, AZ · On-site +1
Experienced in Windows administration, Virtual Desktop Infrastructure (VDI) solutions including Citrix and Azure Virtual Desktop (AVD), Mac OS and Jamf as well as mobile device management.
Lead Infrastructure Engineer
Tempe, AZ · Hybrid
$103K - $135K/yr
Azure Virtual Desktop (AVD) or Windows 365 (W365) experience * Strong critical thinking and problem-solving skills * Excellent written and verbal communication skills with the ability to effectively ...
Lead Infrastructure Engineer
Tempe, AZ · Hybrid
$103K - $135K/yr
Azure Virtual Desktop (AVD) or Windows 365 (W365) experience * Strong critical thinking and problem-solving skills * Excellent written and verbal communication skills with the ability to effectively ...
Staff Engineer II - Active Directory
Phoenix, AZ · Hybrid
$52.50 - $68.50/hr
Configure and troubleshoot Windows desktop environments (AD, GPO) in support of VDI / Azure Virtual Desktop (AVD) deployments. * Provide on-call support for critical identity and directory services ...
Staff Engineer II - Active Directory
Phoenix, AZ · Hybrid
$52.50 - $68.50/hr
Configure and troubleshoot Windows desktop environments (AD, GPO) in support of VDI / Azure Virtual Desktop (AVD) deployments. * Provide on-call support for critical identity and directory services ...
Staff Engineer II - Active Directory
Phoenix, AZ · On-site
$52.50 - $68.50/hr
Configure and troubleshoot Windows desktop environments (AD, GPO) in support of VDI / Azure Virtual Desktop (AVD) deployments. * Provide on-call support for critical identity and directory services ...
Staff Engineer II - Active Directory
Phoenix, AZ · On-site
$52.50 - $68.50/hr
Configure and troubleshoot Windows desktop environments (AD, GPO) in support of VDI / Azure Virtual Desktop (AVD) deployments. * Provide on-call support for critical identity and directory services ...
Microsoft O365, Azure Virtual Desktop and MAC Operating Systems. * Ability to work in fast paced, changing and fast transformational environment against both short-term and long-term requirements.
Microsoft O365, Azure Virtual Desktop and MAC Operating Systems. * Ability to work in fast paced, changing and fast transformational environment against both short-term and long-term requirements.
Microsoft O365, Azure Virtual Desktop and MAC Operating Systems. * Ability to work in fast paced, changing and fast transformational environment against both short-term and long-term requirements.
Microsoft O365, Azure Virtual Desktop and MAC Operating Systems. * Ability to work in fast paced, changing and fast transformational environment against both short-term and long-term requirements.
... and virtual (VMware) desktops • Experience with zero client environment • Ability to ... Azure preferred • Prior military IT operations experience at the Brigade level or higher • ...
... and virtual (VMware) desktops • Experience with zero client environment • Ability to ... Azure preferred • Prior military IT operations experience at the Brigade level or higher • ...
IT Analyst
Phoenix, AZ · On-site
$65K - $75K/yr
Support Citrix virtual desktop environment and VoIP (3CX/Yealink) as needed * Participate in after ... Familiarity with Citrix, VMware, or Azure * SonicWall certification (SNSA or SNSP) a plus * CompTIA ...
IT Analyst
Phoenix, AZ · On-site
$65K - $75K/yr
Support Citrix virtual desktop environment and VoIP (3CX/Yealink) as needed * Participate in after ... Familiarity with Citrix, VMware, or Azure * SonicWall certification (SNSA or SNSP) a plus * CompTIA ...
IT Analyst
Phoenix, AZ · On-site
$65K - $75K/yr
Support Citrix virtual desktop environment and VoIP (3CX/Yealink) as needed * Participate in after ... Familiarity with Citrix, VMware, or Azure * SonicWall certification (SNSA or SNSP) a plus * CompTIA ...
IT Analyst
Phoenix, AZ · On-site
$65K - $75K/yr
Support Citrix virtual desktop environment and VoIP (3CX/Yealink) as needed * Participate in after ... Familiarity with Citrix, VMware, or Azure * SonicWall certification (SNSA or SNSP) a plus * CompTIA ...
IT Analyst
Phoenix, AZ · On-site
$65K - $75K/yr
Support Citrix virtual desktop environment and VoIP (3CX/Yealink) as needed * Participate in after ... Familiarity with Citrix, VMware, or Azure * SonicWall certification (SNSA or SNSP) a plus * CompTIA ...
IT Analyst
Phoenix, AZ · On-site
$65K - $75K/yr
Support Citrix virtual desktop environment and VoIP (3CX/Yealink) as needed * Participate in after ... Familiarity with Citrix, VMware, or Azure * SonicWall certification (SNSA or SNSP) a plus * CompTIA ...
Experience with physical and virtual (VMware) desktops * Experience with zero client environment ... Familiarity with Intune and Azure preferred PREFERRED QUALIFICATIONS * Prior military IT operations ...
Experience with physical and virtual (VMware) desktops * Experience with zero client environment ... Familiarity with Intune and Azure preferred PREFERRED QUALIFICATIONS * Prior military IT operations ...
Experience with physical and virtual (VMware) desktops * Experience with zero client environment ... Familiarity with Intune and Azure preferred PREFERRED QUALIFICATIONS * Prior military IT operations ...
Experience with physical and virtual (VMware) desktops * Experience with zero client environment ... Familiarity with Intune and Azure preferred PREFERRED QUALIFICATIONS * Prior military IT operations ...
Azure Virtual Desktop information
What is the difference between Azure Virtual Desktop vs Cloud Systems Engineer?
| Aspect | Azure Virtual Desktop | Cloud Systems Engineer |
|---|---|---|
| Primary Role | Virtual desktop infrastructure management and deployment | Designing, implementing, and maintaining cloud-based systems |
| Certifications | Azure certifications (e.g., AZ-104, AZ-140) | Cloud certifications (e.g., AWS, Azure, Google Cloud) |
| Work Environment | Cloud platforms, remote desktop environments | Cloud environments, servers, networking |
| Industry Usage | IT support, remote work solutions | Cloud architecture, infrastructure management |
Azure Virtual Desktop focuses on deploying and managing virtual desktops in the cloud, primarily for remote work. Cloud Systems Engineers design and maintain broader cloud infrastructure solutions. While both roles involve cloud technology, Azure Virtual Desktop specialists concentrate on virtual desktop environments, whereas Cloud Systems Engineers handle overall cloud architecture and systems.
What are the key skills and qualifications needed to thrive as an Azure Virtual Desktop Specialist, and why are they important?
What are some common challenges faced by Azure Virtual Desktop administrators, and how can they be addressed?
What is an Azure Virtual Desktop?

Sprouts Farmers Market rating
6.8
Based on 799 frontline employees who took The Breakroom Quiz
22nd of 115 rated grocery stores
Job description
Please note this position is based in our Phoenix, AZ Support Office. The Sr. IT Security Architect is the lead technical architect for Sprouts' IT Security program, designing and driving security architecture across the enterprise.
The Sr. IT Security Architect mentors security engineers and analysts, leads through influence across infrastructure, network, cloud, and application teams, and carries architectural decisions to the Architecture Review Board (ARB) with a recommended path. The role translates business, compliance, and regulatory requirements into concrete, implementable designs and standards that survive implementation and audit.
Sprouts runs an Azure-first cloud stack-including Databricks, Synapse/Fabric, and Azure Virtual Desktop-alongside store systems, point-of-sale, and payment infrastructure under PCI-DSS. The role requires fluency across both. Architectural decisions align with NIST CSF, ISO 27001, CIS Controls, SOX, PCI-DSS, and applicable privacy regulations.
Periodic after-hours or weekend work may be required to support security escalations or major incidents.
Essential FunctionsEssential job functions
Author reference architecture and design documents across all security domains. Designs must be implementable, testable, and resistant to drift.
Lead security architecture positions at the Architecture Review Board (ARB). Define and enforce architectural gates for development-to-production progression. Present options, trade-offs, and a recommended path for each decision.
Lead complex, cross-functional security architecture initiatives of strategic importance to the organization. Advise senior leadership on security matters of significant impact, and provide input to department goals, planning, and budget priorities.
Design and govern Azure landing zones, managed identity patterns, Key Vault and private-endpoint baselines, CSPM policy, and Terraform/Bicep security guardrails. Lead security architecture for Databricks, Synapse, and Fabric data platforms, including data-lake segmentation and access control.
Design integration patterns for Microsoft Entra ID and Okta, conditional access, MFA strategy, B2C customer identity, Azure Virtual Desktop access, and BYOD access. Architect CrowdStrike Identity Protection integration with the identity estate.
Partner with network architecture on segmentation for headquarters and store environments, SASE/CASB/NPA architecture (Netskope), edge protection (Cloudflare), and vendor/BYOD network zones. Drive zero-trust maturity across corporate, retail, and cloud perimeters.
Set architectural direction for EDR/EPP/IDP (CrowdStrike), endpoint management (Tanium), CASB (Netskope), and email security (Proofpoint). Guide the decommissioning of legacy platforms and the onboarding of replacements.
Design DLP, data classification (BigID), consent management, and data retention patterns. Govern the security and privacy architecture of AI platforms, vendors, and internal AI tooling, including model-training and data-handling terms.
Support vendor risk assessments, review SOC 2 Type 2 reports, evaluate vendor SSO/SCIM/RBAC/audit-logging, and author SDLC security standards (secrets management, logging baselines, secure deployment patterns).
Design security architecture for store systems, point-of-sale, handheld devices, and third-party store integrations. Ensure PCI-DSS alignment across applicable environments.
Draft and maintain architectural standards and patterns: naming conventions, IaC security patterns, API gateway baselines, cloud tagging, and logging/compliance defaults.
Map architectural initiatives to NIST CSF (Govern, Identify, Protect, Detect, Respond, Recover), CIS Controls, SOX, and PCI-DSS, borrowing from ISO 27001 and other best practices where applicable. Contribute to security policies and standards.
Provide guidance, coaching, and training in security architecture across the Company within area of expertise - to security engineers and analysts as well as partners in infrastructure, network, cloud, and application teams.
Participate in root cause analysis and architectural remediation for incidents, breaches, and HR/Legal investigations. Translate lessons learned into architectural changes.
Comply with and contribute to change control, development lifecycle, and release management policies. Ensure architectural changes are represented at CAB and documented appropriately.
Knowledge, Skills, Abilities and Physical RequirementsKnowledge Skills & Abilities
Bachelor's degree in Computer Science, Information Technology, Engineering, or equivalent experience in a related discipline.
10+ years of enterprise security architecture experience spanning cloud, identity, network, endpoint, application, and data security.
3+ years of hands-on Azure security architecture: landing zones, Key Vault, managed identity, private endpoints, Microsoft Sentinel, and Azure-native data platforms (Databricks, Synapse, Fabric).
Deep identity architecture experience with core protocols (OAuth/OIDC, SAML, SCIM, federation), conditional access, MFA strategy, and B2C customer identity. Hands-on experience with Microsoft Entra ID and Okta preferred.
Expert-level experience with EDR/EPP and Identity Protection platforms (CrowdStrike preferred).
Expert-level experience with enterprise DLP, data classification (e.g., BigID), and CASB/SASE architecture (Netskope preferred).
Expert-level experience with enterprise email security (Proofpoint preferred) and edge protection (Cloudflare preferred).
Working experience with Infrastructure-as-Code security: Terraform and/or Bicep, policy-as-code, and CSPM platforms.
Fluency with security and compliance frameworks: NIST CSF, CIS Controls, PCI-DSS, SOX, and applicable privacy regulations (CCPA).
Retail, PCI, and store-systems experience strongly preferred (POS, payment, store network, third-party retail integrations).
CISSP, CCSP, or equivalent security certification required.
Demonstrated track record of authoring architecture documentation that survives review, implementation, and audit.
Proficiency with monitoring, logging, change management, and CMDB tooling (ServiceNow experience a plus).
Employment Type: FULL_TIMEWhat Sprouts Farmers Market employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom
About Sprouts
Sourced by ZipRecruiter
Industry
Retail
Company size
10,000+ Employees
Headquarters location
Phoenix, AZ, US
Year founded
2002