Our Company
Oaktree is a leader among global investment managers specializing in alternative investments, with $224 billion in assets under management. The firm emphasizes an opportunistic, value-oriented and risk-controlled approach to investments in credit, private equity, real assets and listed equities. The firm has over 1500 employees and offices in 26 cities worldwide.
We are committed to cultivating an environment that is collaborative, curious, inclusive and honors diversity of thought. Providing training and career development opportunities and emphasizing strong support for our local communities through philanthropic initiatives are essential to our culture.
For additional information please visit our website at www.oaktreecapital.com .
Identity & Security Operations Engineer
Position Summary
We are seeking a hands-on Identity & Security Operations Engineer to support and improve the firm's enterprise identity, access, and security operations capabilities. This role will sit at the intersection of identity administration, identity governance, directory services, access control, authentication, security operations, and compliance.
The ideal candidate has strong operational experience with Saviynt, Microsoft Active Directory, Microsoft Entra ID, privileged access concepts, access governance, and enterprise security controls. This is not a purely governance or policy role. The successful candidate must be comfortable troubleshooting production issues, supporting identity integrations, resolving access and authentication problems, improving operational processes, and partnering with Security, Infrastructure, HRIS, Application, Audit, and Service Desk teams.
This role will be responsible for maintaining reliable identity operations while also helping mature the firm's security posture through stronger access controls, better visibility, automation, lifecycle governance, and secure administration practices.
Key Responsibilities
Identity Governance and Saviynt Operations
- Provide day-to-day operational support for the Saviynt Identity Governance and Administration platform.
- Troubleshoot and resolve complex Saviynt issues involving access requests, entitlement visibility, requestability, certifications, provisioning failures, reconciliation errors, job failures, workflow issues, and user lifecycle events.
- Support onboarding and maintenance of applications, entitlements, roles, owners, approval workflows, and access request models within Saviynt.
- Partner with application owners to validate entitlement mappings, access models, role definitions, and provisioning behavior.
- Support joiner, mover, leaver processes across Workday, Saviynt, Active Directory, Entra ID, and downstream applications.
- Monitor scheduled jobs, connectors, feeds, reconciliations, and provisioning tasks to ensure identity data remains accurate and timely.
- Identify recurring operational issues and recommend process, workflow, connector, or data-quality improvements.
Microsoft Identity Administration
- Administer and support Microsoft Active Directory, Microsoft Entra ID, hybrid identity, directory synchronization, groups, service accounts, privileged groups, and access-related directory objects.
- Troubleshoot authentication, authorization, directory replication, group membership, LDAP, Kerberos, DNS-related identity issues, and Entra ID synchronization problems.
- Support identity-related components such as Entra Connect, conditional access dependencies, enterprise applications, SSO integrations, group-based access, and directory-based provisioning.
- Assist with cleanup and rationalization of legacy identity objects, stale accounts, orphaned groups, privileged access paths, service accounts, and over-permissioned access structures.
- Support secure administration practices across Microsoft identity platforms, including administrative role assignments, privileged group management, break-glass account monitoring, and access reviews.
Security Operations and Access Control
- Partner with Security Operations to investigate identity-related alerts, suspicious sign-ins, access anomalies, risky users, privilege misuse, and potential account compromise events.
- Support enforcement and monitoring of access controls across enterprise platforms, including MFA, Conditional Access, privileged access, least privilege, and separation of duties.
- Assist with security incident response activities where identity data, account access, authentication logs, or entitlement history are required.
- Review identity and access logs to support investigations, audit requests, control validation, and root cause analysis.
- Help improve detection, alerting, and reporting around privileged access, stale access, failed provisioning, unauthorized access changes, and identity lifecycle gaps.
- Support operational controls for high-risk accounts, privileged accounts, service accounts, shared accounts, emergency access accounts, and application administrator access.
Access Governance, Audit