Sasol

Analyst Cybersecurity & Assurance

Sasol  •  South Africa (Onsite)  •  3 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

Sasol is a global integrated chemicals and energy company with a 75-year heritage. Through our talented people, we use our expertise and selected technologies to safely and sustainably source, manufacture and market chemical and energy products globally. When you join Team Sasol, you are joining a company that puts people at the center of everything we do.

Sasol invests in its employees along every stage of the career path and offers development opportunities to help you cultivate your career in a culture that embraces diversity and inclusion.

Job Requisition ID

13095

Closing Date

17 September 2026

OME

CML: Information Management

Location

Sandton, Gauteng

Purpose of Job

Provide first line (operational) assurance to the Cybersecurity team by verifying that security controls are properly designed and operating effectively across core security domains. The role designs and performs control monitoring, testing, gathers evidence and reports objective outcomes against Sasol's IT Critical Cybersecurity Controls (CIS v8.1 mapped to NIST CSF 2.0) and related policies/standards enabling timely remediation and demonstrable compliance. This role is positioned within the Sasol cybersecurity team to drive governance, control monitoring and compliance.

This role focuses on IT security domains only and does not include OT control checks.

Key Accountabilities

Control design assurance

  • Validate control design against internal standards and policies (e.g., AD/Entra ID, PAM, SOC logging, firewall hygiene), raising design gaps and concessions where needed.
  • Translate enterprise control objectives (CIS/NIST CSF) into testable control statements and SOPs for first line checks across identity, endpoint, network, data protection, logging/monitoring, and incident response.
  • Embed doer–checker separation for high-risk activities; ensure evidence trails meet internal and external assurance expectations.

Operating effectiveness & continuous monitoring

  • Plan and execute control tests (periodic and continuous), collecting Outcome-Driven Metrics (ODMs) for the Cyber Safety Score dashboard.
  • Operate configuration/compliance scans and related health checks to detect baseline drift and control exceptions.
  • Coordinate detective control coverage checks (e.g., SIEM use-case health, log onboarding completeness) to assure alert efficacy.

Evidence, reporting & governance

  • Maintain auditable evidence packs mapped to each control/safeguard and to the control library.
  • Produce clear monthly assurance reports highlighting control status, exceptions, risks, and remediation progress for Cyber leadership and Combined Assurance forums.

Issue/exception handling and risk response

  • Drive remediation tracking with control owners; log and monitor risk responses and concessions per the Cybersecurity Risk Response process.
  • Support SOX/ITGC sustainment by aligning first-line checks to key access/change/configuration controls and collating compensating-control evidence where needed.

Stakeholder collaboration (2nd/3rd line)

  • Partner with GRC/Compliance (2nd line) and Internal Audit (3rd line) to share first-line results, close findings, and reduce repeat issues via design improvements and SOP updates.

Technical Skill

  • Frameworks/Controls: NIST CSF 2.0; CIS Controls v8.1; ISO/IEC 27001
  • IAM & PAM; Network & Perimeter Security; Endpoint/Server Protection
  • Security Logging & Monitoring; Incident Response linkage
  • Change & Configuration Management; configuration baseline drift detection and evidence capture
  • Data Security & Protection; backup/recovery verification

Formal Education

  • 3–4 year relevant degree (Information Security / Computer Science / Risk / Audit) or equivalent

Formal Experience

6 years experience in cybersecurity operations or control monitoring/assurance across cybersecurity domains.

Certification & Professional Membership

One or more of the following will be advantageous:

  • Security Operations / Controls: CompTIA Security+, (ISC)² SSCP, CCSP, CISA,CISSP
  • Governance/Standards: ISO/IEC 27001 Lead Implementer/Lead Auditor
  • Microsoft Security/IAM: SC-200, SC-300, SC-100, AZ-500
  • PAM/IAM: vendor certifications (e.g., CyberArk, Omada)
  • SOX compliance certifications

Required Personal and Professional Skills

BC_Nimble Learning

BC_Communicates Effectively

TC_IM Data Analytics

TC_IT Risk, Control, and Security

BC_Manages Complexity

TC_Assessment

BC_Tech Savvy

TC_Compliance Management

TC_Information Management

BC_Ensures Accountability

TC_G_Stakeholder Relationship Management

Sasol is an equal opportunity and affirmative action employer. Inspired by our Purpose of “Innovating for a better world”, Sasol acknowledges that diversity is intrinsic to the fabric of our organisation and is the key to our growth and success. Sasol is committed to the full inclusion of all suitably qualified individuals. Preference will be given to applicants from designated groups and people with disabilities according to Sasol’s Employment Equity Plan. This includes reasonable accommodation to enable individuals with disabilities to perform essential job functions.

Our automated process is designed to efficiently assess a large volume of applications. Should you not hear from us within 60 days of the advert closing then kindly consider your application unsuccessful. Thank you once-more for your interest in Sasol as your employer of choice, and we wish you all the best with your career aspirations and future applications with us.

Sasol

About Sasol

Sasol is a global chemicals and energy company. We harness our knowledge and expertise to integrate sophisticated technologies and processes into world-scale operating facilities.

We safely and sustainably source, produce and market a range of high-quality products in 22 countries, creating value for stakeholders.

Our revised strategy aims to have a greater focus on value realisation for our stakeholders, sustainable growth and improved business sustainability as well as enhanced cash generation. The Chemicals Business will grow by meeting evolving consumer needs, including the demands of a growing and urbanising middle class. It will focus its activities on specialty chemicals where it has differentiated capabilities and strong market positions that can be expanded over time. The Energy Business will position to be responsive to global trends by providing new energy and mobility solutions over time, pursuing greenhouse gas emission reductions through growth in gas and renewables, and higher cash generation.

Terms of use:

While we encourage a multitude of views and opinions on this forum, any comments that contain spam (irrelevant links/self-promotion), hate speech, undue negativity or foul language will be removed.

Fraud Alert!

Sasol's recruitment process does not include unsolicited offers of employment and also does not require advance payments from candidates. Sasol will only contact you if you have applied for a vacancy through the career website, the official Sasol LinkedIn page or if you were contacted by one of our authorised recruitment personnel or local recruiting office.

Sasol will not ask you to send personal banking information via email. If you suspect fraud, you are encouraged to alert Sasol by sending an e-mail to recruitmentfraud@sasol.com. Alternatively please report such activity to your local law enforcement authorities.

Industry
Chemicals & Materials
Company Size
10,000+ employees
Headquarters
Sandton, ZA
Year Founded
1950
Website
sasol.com
Social Media