×
Register Here to Apply for Jobs or Post Jobs. X

Analyst Cybersecurity & Assurance

Job in Sandton, 2172, South Africa
Listing for: Sasol Limited
Full Time position
Listed on 2026-09-07
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Job Description & How to Apply Below

Analyst Cybersecurity & Assurance

Posting Date: Sep 4, 2026

Company: Sasol

Sasol is a global integrated chemicals and energy company with a 75-year heritage. Through our talented people, we use our expertise and selected technologies to safely and sustainably source, manufacture and market chemical and energy products globally. When you join Team Sasol, you are joining a company that puts people at the center of everything we do.

Sasol invests in its employees along every stage of the career path and offers development opportunities to help you cultivate your career in a culture that embraces diversity and inclusion.

Job

Requisition

13095

CML:
Information Management

Purpose of Job

Provide first line (operational) assurance to the Cybersecurity team by verifying that security controls are properly designed and operating effectively across core security domains. The role designs and performs control monitoring, testing, gathers evidence and reports objective outcomes against Sasol's IT Critical Cybersecurity Controls (CIS v8.1 mapped to NIST CSF 2.0) and related policies/standards enabling timely remediation and demonstrable compliance. This role is positioned within the Sasol cybersecurity team to drive governance, control monitoring and compliance.

This role focuses on IT security domains only and does not include OT control checks.

Key Accountabilities
  • Validate control design against internal standards and policies (e.g., AD/Entra , PAM, SOC logging, firewall hygiene), raising design gaps and concessions where needed.
  • Translate enterprise control objectives (CIS/NIST CSF) into testable control statements and SOPs for first line checks across identity, endpoint, network, data protection, logging/monitoring, and incident response.
  • Embed doer–checker separation for high-risk activities; ensure evidence trails meet internal and external assurance expectations.

Operating effectiveness & continuous monitoring

  • Plan and execute control tests (periodic and continuous), collecting Outcome-Driven Metrics (ODMs) for the Cyber Safety Score dashboard.
  • Operate configuration/compliance scans and related health checks to detect baseline drift and control exceptions.

Evidence, reporting & governance

  • Maintain auditable evidence packs mapped to each control/safeguard and to the control library.
  • Produce clear monthly assurance reports highlighting control status, exceptions, risks, and remediation progress for Cyber leadership and Combined Assurance forums.

Issue/exception handling and risk response

  • Drive remediation tracking with control owners; log and monitor risk responses and concessions per the Cybersecurity Risk Response process.
  • Support SOX/ITGC sustainment by aligning first-line checks to key access/change/configuration controls and collating compensating-control evidence where needed.

Stakeholder collaboration (2nd/3rd line)

  • Partner with GRC/Compliance (2nd line) and Internal Audit (3rd line) to share first-line results, close findings, and reduce repeat issues via design improvements and SOP updates.
Technical Skill
  • Frameworks/Controls: NIST CSF 2.0; CIS Controls v8.1; ISO/IEC 27001
  • Security Logging & Monitoring;
    Incident Response linkage
  • Change & Configuration Management; configuration baseline drift detection and evidence capture
  • Data Security & Protection; backup/recovery verification
Formal Education
  • 3–4 year relevant degree (Information Security / Computer Science / Risk / Audit) or equivalent
Formal Experience

6 years experience in cybersecurity operations or control monitoring/assurance across cybersecurity domains.

Certification & Professional Membership

One or more of the following will be advantageous:

  • Security Operations / Controls:
    CompTIA Security+, (ISC)² SSCP, CCSP, CISA,CISSP
  • Microsoft Security/IAM: SC-200, SC-300, SC-100, AZ-500
  • PAM/IAM: vendor certifications (e.g., Cyber Ark, Omada)
  • SOX compliance certifications
Required Personal and Professional Skills

Learning

Effectively

Data Analytics

Risk, Control, and Security

Complexity

Savvy

Management

Management

Accountability

TC_G_Stakeholder Relationship Management

Sasol is an equal opportunity and affirmative action employer. Inspired by our Purpose of “Innovating for a…

Position Requirements
5+ Years work experience
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary