Analyst Cybersecurity & Assurance

Sasol

Sandton

On-site

ZAR 900,000 - 1,500,000

Full time

2 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Sasol is seeking an experienced cybersecurity assurance professional in Sandton to verify that controls are properly designed and operating across core domains. You will design, test and monitor controls, gather evidence, and report outcomes to enable timely remediation and compliance.

The role focuses on IT security domains, supports SOX/ITGC, and requires collaboration with GRC, Compliance and Internal Audit. A relevant degree and 6+ years of experience are expected.

Qualifications

  • 3–4 year degree in Information Security / Computer Science or equivalent.
  • 6 years experience in cybersecurity operations or control monitoring across domains.
  • Familiarity with CIS/NIST CSF frameworks and ITGC/SOX controls.

Responsibilities

  • Design and test controls; monitor effectiveness and evidence trails.
  • Produce monthly assurance reports for leadership and governance.
  • Collaborate with 2nd/3rd line to close findings and improve controls.

Skills

NIST CSF 2.0
CIS Controls v8.1
ISO/IEC 27001
IAM & PAM
Network Security
Endpoint/SERVER Protection
Security Logging
Incident Response
Change Management
Data Protection

Education

Degree in Information Security / CS

Tools

CyberArk
Omada
Microsoft SC-200/SC-300/SC-100/AZ-500
CISA
CISSP

Job description

Sasol is a global integrated chemicals and energy company with a 75-year heritage. Through our talented people, we use our expertise and selected technologies to safely and sustainably source, manufacture and market chemical and energy products globally. When you join Team Sasol, you are joining a company that puts people at the center of everything we do.

Sasol invests in its employees along every stage of the career path and offers development opportunities to help you cultivate your career in a culture that embraces diversity and inclusion.

Sandton, Gauteng

Purpose of Job

Provide first line (operational) assurance to the Cybersecurity team by verifying that security controls are properly designed and operating effectively across core security domains. The role designs and performs control monitoring, testing, gathers evidence and reports objective outcomes against Sasol's IT Critical Cybersecurity Controls (CIS v8.1 mapped to NIST CSF 2.0) and related policies/standards enabling timely remediation and demonstrable compliance. This role is positioned within the Sasol cybersecurity team to drive governance, control monitoring and compliance.

This role focuses on IT security domains only and does not include OT control checks.

Key Accountabilities
Control design assurance
  • Validate control design against internal standards and policies (e.g., AD/Entra ID, PAM, SOC logging, firewall hygiene), raising design gaps and concessions where needed.
  • Translate enterprise control objectives (CIS/NIST CSF) into testable control statements and SOPs for first line checks across identity, endpoint, network, data protection, logging/monitoring, and incident response.
  • Embed doer-catcher separation for high-risk activities; ensure evidence trails meet internal and external assurance expectations.
Operating effectiveness & continuous monitoring
  • Plan and execute control tests (periodic and continuous), collecting Outcome-Driven Metrics (ODMs) for the Cyber Safety Score dashboard.
  • Operate configuration/compliance scans and related health checks to detect baseline drift and control exceptions.
  • Coordinate detective control coverage checks (e.g., SIEM use-case health, log onboarding completeness) to assure alert efficacy.
Evidence, reporting & governance
  • Maintain auditable evidence packs mapped to each control/safeguard and to the control library.
  • Produce clear monthly assurance reports highlighting control status, exceptions, risks, and remediation progress for Cyber leadership and Combined Assurance forums.
Issue/exception handling and risk response
  • Drive remediation tracking with control owners; log and monitor risk responses and concessions per the Cybersecurity Risk Response process.
  • Support SOX/ITGC sustainment by aligning first-line checks to key access/change/configuration controls and collating compensating-control evidence where needed.
Stakeholder collaboration (2nd/3rd line)
  • Partner with GRC/Compliance (2nd line) and Internal Audit (3rd line) to share first-line results, close findings, and reduce repeat issues via design improvements and SOP updates.
Technical Skill
  • Frameworks/Controls: NIST CSF 2.0; CIS Controls v8.1; ISO/IEC 27001
  • IAM & PAM; Network & Perimeter Security; Endpoint/Server Protection
  • Security Logging & Monitoring; Incident Response linkage
  • Change & Configuration Management; configuration baseline drift detection and evidence capture
  • Data Security & Protection; backup/recovery verification
Formal Education
  • 3–4 year relevant degree (Information Security / Computer Science / Risk / Audit) or equivalent
Formal Experience

6 years experience in cybersecurity operations or control monitoring/assurance across cybersecurity domains.

Certification & Professional Membership
  • Security Operations / Controls: CompTIA Security+, (ISC)² SSCP, CCSP, CISA,CISSP
  • Governance/Standards: ISO/IEC 27001 Lead Implementer/Lead Auditor
  • Microsoft Security/IAM: SC-200, SC-300, SC-100, AZ-500
  • PAM/IAM: vendor certifications (e.g., CyberArk, Omada)
  • SOX compliance certifications
Required Personal And Professional Skills
  • BC_Nimble Learning
  • BC_Communicates Effectively
  • TC_IM Data Analytics
  • TC_IT Risk, Control, and Security
  • BC_Manages Complexity
  • TC_Assessment
  • BC_Tech Savvy
  • TC_Compliance Management
  • TC_Information Management
  • BC_Ensures Accountability
  • TC_G_Stakeholder Relationship Management

Sasol is an equal opportunity and affirmative action employer. Inspired by our Purpose of “Innovating for a better world”, Sasol acknowledges that diversity is intrinsic to the fabric of our organisation and is the key to our growth and success. Sasol is committed to the full inclusion of all suitably qualified individuals. Preference will be given to applicants from designated groups and people with disabilities according to Sasol’s Employment Equity Plan. This includes reasonable accommodation to enable individuals with disabilities to perform essential job functions.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Analyst Cybersecurity & Assurance
Analyst Cybersecurity & Assurance

Sasol Limited • Sandton

On-site
ZAR 900,000 - 1,300,000
Cyber Assurance Analyst – Controls & Compliance
Cyber Assurance Analyst – Controls & Compliance

Sasol • Sandton

On-site
ZAR 900,000 - 1,500,000
Cybersecurity Assurance Analyst — Governance & Compliance
Cybersecurity Assurance Analyst — Governance & Compliance

Sasol Limited • Sandton

On-site
ZAR 900,000 - 1,300,000
Instruments & Controls Foreman
Instruments & Controls Foreman

Sasol Limited • South Africa

On-site
ZAR 850,000 - 1,100,000
Chief Technician Process
Chief Technician Process

Sasol Limited • Secunda

On-site
ZAR 900,000 - 1,200,000
Technician II Process
Technician II Process

Sasol Limited • Secunda

On-site
ZAR 300,000 - 420,000
Process Technologist II CA & Utilities
Process Technologist II CA & Utilities

Sasol • Sasolburg

On-site
ZAR 700,000 - 1,000,000
Instruments & Control Engineer I
Instruments & Control Engineer I

Sasol • Secunda

On-site
ZAR 600,000 - 900,000
Analyst Data Enablement
Analyst Data Enablement

Sasol • Sandton

On-site
ZAR 700,000 - 1,100,000
Process Technologist II CA & Utilities
Process Technologist II CA & Utilities

Sasol Limited • South Africa

On-site
ZAR 420,000 - 660,000