You can configure your EJBs to use the J2EE security services that OC4J provides.
For more information, see:
"Configuring Security Services"
Oracle Application Server Security Guide