459,924open jobs
15,541companies
67,347added this week
Browse all
Salary
$20k – $46k per year (Estimated)
Location
In office (Hyderabad)
Seniority
Senior · 5+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Oaktree Capital Management is an alternative investment management firm headquartered in Los Angeles, California, and founded in 1995 by Howard Marks, Bruce Karsh, and a group of colleagues from TCW. The firm specializes in credit strategies, including distressed debt, high yield bonds, private credit, real estate, and listed equities. It manages roughly 200 billion dollars in assets for institutional and individual investors and has been majority owned by Brookfield Asset Management since 2019.

Our Company

Oaktree is a leader among global investment managers specializing in alternative investments, with $224 billion in assets under management. The firm emphasizes an opportunistic, value-oriented and risk-controlled approach to investments in credit, private equity, real assets and listed equities. The firm has over 1500 employees and offices in 26 cities worldwide.

We are committed to cultivating an environment that is collaborative, curious, inclusive and honors diversity of thought. Providing training and career development opportunities and emphasizing strong support for our local communities through philanthropic initiatives are essential to our culture.

For additional information please visit our website at www.oaktreecapital.com.

Identity & Security Operations Engineer

Position Summary

We are seeking a hands-on Identity & Security Operations Engineer to support and improve the firm’s enterprise identity, access, and security operations capabilities. This role will sit at the intersection of identity administration, identity governance, directory services, access control, authentication, security operations, and compliance.

The ideal candidate has strong operational experience with Saviynt, Microsoft Active Directory, Microsoft Entra ID, privileged access concepts, access governance, and enterprise security controls. This is not a purely governance or policy role. The successful candidate must be comfortable troubleshooting production issues, supporting identity integrations, resolving access and authentication problems, improving operational processes, and partnering with Security, Infrastructure, HRIS, Application, Audit, and Service Desk teams.

This role will be responsible for maintaining reliable identity operations while also helping mature the firm’s security posture through stronger access controls, better visibility, automation, lifecycle governance, and secure administration practices.

Key Responsibilities

Identity Governance and Saviynt Operations

Provide day-to-day operational support for the Saviynt Identity Governance and Administration platform.

Troubleshoot and resolve complex Saviynt issues involving access requests, entitlement visibility, requestability, certifications, provisioning failures, reconciliation errors, job failures, workflow issues, and user lifecycle events.

Support onboarding and maintenance of applications, entitlements, roles, owners, approval workflows, and access request models within Saviynt.

Partner with application owners to validate entitlement mappings, access models, role definitions, and provisioning behavior.

Support joiner, mover, leaver processes across Workday, Saviynt, Active Directory, Entra ID, and downstream applications.

Monitor scheduled jobs, connectors, feeds, reconciliations, and provisioning tasks to ensure identity data remains accurate and timely.

Identify recurring operational issues and recommend process, workflow, connector, or data-quality improvements.

Microsoft Identity Administration

Administer and support Microsoft Active Directory, Microsoft Entra ID, hybrid identity, directory synchronization, groups, service accounts, privileged groups, and access-related directory objects.

Troubleshoot authentication, authorization, directory replication, group membership, LDAP, Kerberos, DNS-related identity issues, and Entra ID synchronization problems.

Support identity-related components such as Entra Connect, conditional access dependencies, enterprise applications, SSO integrations, group-based access, and directory-based provisioning.

Assist with cleanup and rationalization of legacy identity objects, stale accounts, orphaned groups, privileged access paths, service accounts, and over-permissioned access structures.

Support secure administration practices across Microsoft identity platforms, including administrative role assignments, privileged group management, break-glass account monitoring, and access reviews.

Security Operations and Access Control

Partner with Security Operations to investigate identity-related alerts, suspicious sign-ins, access anomalies, risky users, privilege misuse, and potential account compromise events.

Support enforcement and monitoring of access controls across enterprise platforms, including MFA, Conditional Access, privileged access, least privilege, and separation of duties.

Assist with security incident response activities where identity data, account access, authentication logs, or entitlement history are required.

Review identity and access logs to support investigations, audit requests, control validation, and root cause analysis.

Help improve detection, alerting, and reporting around privileged access, stale access, failed provisioning, unauthorized access changes, and identity lifecycle gaps.

Support operational controls for high-risk accounts, privileged accounts, service accounts, shared accounts, emergency access accounts, and application administrator access.

Access Governance, Audit, and Compliance

Support access certification campaigns, entitlement reviews, privileged access reviews, and compliance-driven access validation activities.

Partner with Audit, Compliance, Risk, and application owners to gather evidence, validate access controls, and remediate access findings.

Help maintain control documentation for identity lifecycle management, access provisioning, deprovisioning, privileged access, role-based access, and access review processes.

Investigate and remediate access exceptions, orphaned entitlements, inappropriate access, excessive privileges, and failed deprovisioning events.

Support control testing for SOX, SOC, internal audit, regulatory examinations, and other compliance requirements.

Ensure identity operations are performed in accordance with firm policies, security standards, and documented procedures.

Identity Integrations and Application Support

Support identity integrations between Workday, Saviynt, Active Directory, Entra ID, ServiceNow, and enterprise applications.

Troubleshoot identity data flow issues, attribute mismatches, provisioning failures, connector errors, group assignment problems, and access synchronization issues.

Work with application teams to define access models, entitlement structures, approval workflows, provisioning requirements, and access review expectations.

Assist with onboarding new applications into identity governance, SSO, lifecycle management, or access review processes.

Support SAML, OIDC, LDAP, and directory-based access patterns from an operations and troubleshooting perspective.

Automation, Reporting, and Continuous Improvement

Develop and maintain scripts, reports, queries, dashboards, and operational checks to improve IAM reliability and visibility.

Use PowerShell, SQL, Python, Saviynt reporting, Entra admin tools, and ITSM data to identify trends, recurring issues, control gaps, and automation opportunities.

Create repeatable procedures for common IAM operations, access corrections, incident response support, application onboarding, and audit evidence collection.

Improve documentation, knowledge base articles, runbooks, troubleshooting guides, and handoff materials for IAM and Service Desk teams.

Participate in change management, incident management, problem management, and post-incident reviews.

Required Qualifications

5+ years of experience in Identity and Access Management, identity operations, security operations, directory services, or access administration.

3+ years of hands-on experience administering or supporting Saviynt in an enterprise environment.

Strong working knowledge of identity governance, access provisioning, access certifications, entitlement management, RBAC, identity lifecycle management, and joiner/mover/leaver processes.

Strong hands-on experience with Microsoft Active Directory and Microsoft Entra ID.

Experience troubleshooting authentication, authorization, directory, synchronization, group membership, provisioning, and access-related issues.

Experience supporting Workday-to-IAM or HR-driven identity lifecycle integrations.

Understanding of security operations concepts, including account compromise investigation, privileged access monitoring, access anomalies, and identity-related incident response.

Experience supporting audit, compliance, access reviews, evidence gathering, and control remediation.

Working knowledge of SSO, SAML, OIDC, LDAP, Kerberos, MFA, Conditional Access, and hybrid identity concepts.

Strong scripting or reporting experience using PowerShell, SQL, Python, or similar tools.

Strong analytical, troubleshooting, documentation, and communication skills.

Ability to work with technical teams, application owners, business stakeholders, auditors, and security teams.

Preferred Qualifications

Saviynt certification or formal Saviynt training.

Microsoft identity or security certifications.

Experience with privileged access management platforms such as CyberArk, Delinea, BeyondTrust, or Microsoft Entra Privileged Identity Management.

Experience with ServiceNow or another enterprise ITSM platform.

Experience with Microsoft Defender, Entra ID Protection, Sentinel, Splunk, or other SIEM/security monitoring tools.

Experience in financial services, asset management, investment management, or another regulated enterprise environment.

Experience supporting SOX, SOC, SEC, FINRA, HIPAA, or similar control frameworks.

Experience with API-based integrations, connector troubleshooting, identity data transformation, or IAM workflow design.

Familiarity with Zero Trust principles, least privilege, separation of duties, and privileged access governance.

Core Competencies

Strong hands-on operational mindset.

Ability to troubleshoot complex identity and access issues across multiple systems.

Security-focused approach to identity administration and access control.

Strong understanding of how identity, access, authentication, and security operations intersect.

Ability to identify root causes and drive long-term fixes, not just one-time access corrections.

Comfortable working in a complex, high-control enterprise environment.

Strong documentation discipline and attention to detail.

Ability to communicate clearly with both technical and non-technical stakeholders.

Tools and Technologies

Saviynt Identity Governance and Administration

Microsoft Active Directory

Microsoft Entra ID

Entra Connect

Conditional Access

Microsoft MFA

Privileged Identity Management

Workday

ServiceNow

PowerShell

SQL

Python

SAML

OIDC

LDAP

Kerberos

Microsoft Defender

SIEM tools such as Sentinel or Splunk

Privileged access management platforms

Windows Server identity services

Success Measures

Improved stability and reliability of Saviynt operations.

Faster resolution of provisioning, reconciliation, access request, and identity lifecycle issues.

Improved access visibility and entitlement accuracy.

Reduced stale, orphaned, excessive, or inappropriate access.

Stronger privileged access monitoring and operational controls.

Improved audit readiness and faster evidence collection.

Better integration between IAM operations, security operations, and application access management.

Clearer documentation, runbooks, and support processes.

Measurable reduction in recurring IAM incidents and manual access correction work.

Equal Opportunity Employment Policy

Oaktree is committed to diversity and to equal opportunity employment. Oaktree does not make employment decisions on the basis of race, creed, color, ethnicity, national origin, citizenship, religion, sex, sexual orientation, gender identity, gender expression, age, past or present physical or mental disability, HIV status, medical condition as defined by state law (genetic characteristics or cancer), pregnancy, childbirth and related medical conditions, veteran status, military service, marital status, familial status, genetic information, domestic violence victim status or any other classification protected by applicable federal, state and local laws and ordinances. This policy applies to hiring, placement, internal promotions, training, opportunities for advancement, recruitment advertising, transfers, demotions, layoffs, terminations, recruitment advertising, rates of pay and other forms of compensation and all other terms, conditions and privileges of employment.

This policy applies to all Oaktree applicants, employees, clients, and contractors.

Equal Opportunity Employment Policy

Oaktree is committed to diversity and to equal opportunity employment. Oaktree does not make employment decisions on the basis of race, creed, color, ethnicity, national origin, citizenship, religion, sex, sexual orientation, gender identity, gender expression, age, past or present physical or mental disability, HIV status, medical condition as defined by state law (genetic characteristics or cancer), pregnancy, childbirth and related medical conditions, veteran status, military service, marital status, familial status, genetic information, domestic violence victim status or any other classification protected by applicable federal, state and local laws and ordinances. This policy applies to hiring, placement, internal promotions, training, opportunities for advancement, recruitment advertising, transfers, demotions, layoffs, terminations, recruitment advertising, rates of pay and other forms of compensation and all other terms, conditions and privileges of employment. This policy applies to all Oaktree applicants, employees, clients, and contractors. Staff members wishing to report violations or suspected violations of this policy should contact the head of their department or Human Resources.

For positions based in Los Angeles

For those applying for a position in the city of Los Angeles, the firm will consider for employment qualified applicants with a criminal history in a manner consistent with applicable federal, state and local law.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
459,924 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Hyderabad
$80k – $222k per year (Estimated) • In office • Full-Time • 7+ years exp • PhD • London
Python
JavaScript
SQL
Apex
Apex
MuleSoft
Databases
Snowflake
Databricks
Google BigQuery
Amazon Redshift
BigQuery
AI/ML
Copilot
Model Context Protocol
Vertex AI
Prompt Engineering
Multimodal AI
AI Agents
TensorFlow
PyTorch
Gemini
Amazon SageMaker
Agentforce
A2A
Vertex AI Agent Builder
DevOps
AWS
Apply
$110k – $148k per year • In office • Full-Time • 7+ years exp • PhD • Milan
Python
JavaScript
SQL
Apex
Apex
MuleSoft
Databases
Snowflake
Databricks
Google BigQuery
Amazon Redshift
BigQuery
AI/ML
Copilot
Model Context Protocol
Vertex AI
Prompt Engineering
Multimodal AI
AI Agents
TensorFlow
PyTorch
Gemini
Amazon SageMaker
Agentforce
A2A
Vertex AI Agent Builder
DevOps
AWS
Apply
$109k – $210k per year • Remote/Hybrid • Full-Time • 8+ years exp • Bachelor's Degree • Alpharetta
Python
SQL
Robotics
Digital Twin
Analytics
Power BI
Apply
$73k – $165k per year (Estimated) • Remote • Full-Time • 2+ years exp • United States
Python
JavaScript
TypeScript
Node JS
Frontend
Vue.js
GraphQL
Angular
React.js
DevOps
Terraform
GitHub Actions
GitLab CI
CI/CD
Jenkins
AWS
Docker
Kubernetes
AWS Lambda
GitHub
GitLab
IAM
Cybersecurity
Zero Trust
Microsoft Entra ID
Apply
$90k – $145k per year • Equity • In office • Full-Time • 8+ years exp • Bachelor's Degree • Towson
SQL
DevOps
Azure DevOps
Azure
Analytics
Tableau
Power BI
ETL/ELT
Management
Jira
ServiceNow
Apply
$21k – $50k per year (Estimated) • Remote/Hybrid • Full-Time • 10+ years exp • Bachelor's Degree • Hyderabad
Python
Go
JavaScript
TypeScript
SQL
C#
C++
Scala
C#
ASP.NET Core
Entity Framework Core
gRPC for .NET
Databases
PostgreSQL
RabbitMQ
Apache Kafka
Azure Cosmos DB
Frontend
React.js
DevOps
Rest API
gRPC
Terraform
Azure
CI/CD
Docker
Kubernetes
Bicep
Azure AKS
Analytics
ETL/ELT
Apply
$170k – $200k per year • In office • Full-Time • 8+ years exp • Bachelor's Degree • Los Angeles
DevOps
CI/CD
FinOps
Management
ServiceNow
Apply
$27k – $57k per year (Estimated) • In office • Full-Time • 8+ years exp • Bachelor's Degree • Hyderabad
Analytics
Microsoft Excel
Apply
$17k – $37k per year (Estimated) • In office • Full-Time • 7+ years exp • Bachelor's Degree • Hyderabad
AI/ML
Copilot
ChatGPT
Management
Outlook
Apply
$17k – $37k per year (Estimated) • In office • Full-Time • 5+ years exp • Bachelor's Degree • Hyderabad
Analytics
Microsoft Excel
Apply
See all jobs
This is one of many
459,924 more open roles from verified company boards, updated every day.