PCI Compliance Analyst

GFL Environmental Inc.

Vaughan

On-site

CAD 90,000 - 120,000

Full time

12 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Health insurance
Wellness program
RRSP matching
Profit sharing
Career growth opportunities

Job summary

GFL Environmental Inc. in Vaughan is seeking an IT Compliance & Quality Assurance Specialist (PCI / GRC) to strengthen our controls across the IT enterprise. You will test, monitor, and improve PCI DSS v4.0 and SOX compliance, collaborating with IT, Security, Finance, and external auditors.

The role emphasizes risk-based remediation, control testing, and program maturation with opportunities to automate GRC processes and influence policy updates. Join Team Green.

Qualifications

  • 3–5 years of hands-on information security, risk management, QA, or regulatory compliance experience.
  • Education: post-secondary in technology, auditing, or related field.
  • Deep knowledge of PCI DSS, SOX ITGC & ITAC, and regulatory frameworks (NIST, COSO, COBIT).
  • Strong communication and cross-functional collaboration skills.

Responsibilities

  • Test and validate PCI DSS & SOX controls, data flows, and configurations.
  • Review audit docs (ROCs/SAQs) and manage remediation actions.
  • Map controls to PCI DSS Risk Control Matrix and define KRIs.
  • Drive automation across the GRC function and update policies.
  • Collaborate with internal teams and external auditors to present status.

Skills

PCI DSS expertise
SOX ITGC & ITAC
Frameworks (NIST, COSO, COBIT)
Cloud security
Data protection controls
Project management
Communication skills
ISA designation (historical)

Education

Post-secondary education in technology, auditing, or related field

Job description

Ready to elevate your career? GFL is expanding! We are officially hunting for our next IT Compliance & Quality Assurance Specialist (PCI / GRC) in Vaughan—someone ready to bring fresh ideas and grow alongside a dynamic team.

About Us

GFL is one of the largest diversified environmental services companies in North America, providing comprehensive solid waste management services from its platform of facilities throughout Canada and 18 U.S. states. Recognized by our signature fleet of bright green trucks and equipment, we offer a wide range of environmental and industrial services to businesses, communities and households, providing a consolidated and sophisticated approach to meeting ou r customers’ needs. One of the keys to our success lies in the diversity of our services and our ability to deliver ro bust integrated solutions, all from a single efficient company. We believe that, by providing safe, accessible and cost-effective solutions, we encourage greater environmental responsibility and allow our customers and the communities we serve to be Green for Life.

The Role

We are looking for a talented IT Compliance & Quality Assurance Specialist to join our team. In this role, you will play a crucial role in building compliance across the IT enterprise by monitoring, testing, and evaluating internal controls and security reports to ensure alignment with PCI DSS v4.0 and SOX requirements. You will work closely with IT, Security, Product, Finance, and external audit teams to identify non-compliance areas, manage remediation plans, and safeguard sensitive cardholder data across GFL's IT platform. The role reports to the Information Technology GRC Manager.

Key Responsibilities
  • PCI DSS & SOX Control Testing: Test and validate security controls, network diagrams, data flows, and system configurations against PCI DSS v4.0 requirements while balancing SOX Control Self-Assessments.

  • Audit & Remediation Management: Review ROCs/SAQs, manage audit documentation, track identified vulnerabilities or non-compliance findings, and collaborate with IT teams to verify corrective actions.

  • Risk & GRC Integration: Map general controls to the PCI DSS Risk Control Matrix (RCM), catalog in-scope environments, define Key Risk Indicators (KRIs), and integrate PCI requirements into the IT Compliance Control Self-Assessment process.

  • Program Maturation & Automation: Drive automation across the GRC function, update compliance policies and SOPs, and assess new IT projects during planning phases for PCI DSS design and worthiness.

  • Stakeholder & Auditor Collaboration: Partner with internal teams and external auditors through assessments, presenting compliance status, metrics, and QA findings confidently to management and leadership.

What We’re Looking For
  • Experience: 3–5 years of hands‑paced experience in information security, risk management, quality assurance, or regulatory compliance within a fast‑paced environment.

  • Education: Post‑secondary education, preferably in technology, auditing, or a related field.

  • Technical Skills: Deep knowledge of PCI DSS (including SAQ requirements for Level 2+ merchants), SOX IT General & Application controls, regulatory frameworks (NIST, COSO, COBIT), cloud computing security, network/data protection controls (NAC, DLP), and API/scanning mechanisms (AVS). Held an Internal Security Assessor (ISA) designation at one point in time.

  • Soft Skills: Excellent written and verbal communication skills with the ability to convey complex technical topics to senior leaders, strong project management skills, and the ability to collaborate across technical and non‑technical teams.

  • Bonus Points: Industry credentials such as CISA, CISSP, CISM, AAIA, or PCIP; experience in the Tech Sector; familiarity with data privacy regulations (GDPR, PIPEDA).

What We Offer

Why join us? We believe in taking care of our team. Here is a snapshot of our total rewards you can expect:

  • Health: Comprehensive medical, dental, and vision insurance.

  • Wellness: Employee Assistance Program, life insurance, and paid time‑off.

  • Financial: RRSP matching, profit sharing and competitive wages.

  • Culture: Growth opportunities and continuous learning opportunities.

Join us and become part of "Team Green" at GFL Environmental, where your skills and dedication will be valued and rewarded.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

PCI & IT GRC Compliance Specialist
PCI & IT GRC Compliance Specialist

GFL Environmental Inc. • Vaughan

On-site
CAD 90,000 - 120,000
Health insurance
Wellness program
RRSP matching
+2
Workday Finance Analyst
Workday Finance Analyst

GFL Environmental Inc. • Vaughan

On-site
CAD 70,000 - 95,000
Health insurance
Wellness program
Life insurance
+3
Human Resources Business Partner
Human Resources Business Partner

GFL Environmental Inc. • Mississauga

On-site
CAD 90,000 - 130,000
Health insurance
Employee Assistance Program
RRSP matching
+1
Administrator
Administrator

GFL Environmental Inc. • San Juan de Terranova

On-site
CAD 36,000 - 48,000
RRSP matching program
Health, Vision and Dental Coverage
Employee Assistance Programs
+2
HR Project Manager
HR Project Manager

GFL Environmental Inc. • Vaughan

On-site
CAD 90,000 - 130,000
Health benefits
Wellness programs
RRSP matching & profit sharing
+1
Executive Assistant
Executive Assistant

GFL Environmental Inc. • Vaughan

On-site
CAD 60,000 - 90,000
Health insurance
Wellness program
RRSP matching
+1
Gestionnaire régional(e) Santé et Sécurité / Regional Health & Safety Manager
Gestionnaire régional(e) Santé et Sécurité / Regional Health & Safety Manager

GFL Environmental Inc. • Châteauguay

Hybrid
CAD 90,000 - 120,000
Health insurance
RRSP matching
Professional development
National Talent Acquisition Business Partner
National Talent Acquisition Business Partner

UNKNOWN • Vaughan

On-site
CAD 90,000 - 120,000
Health insurance
Wellness program
RRSP matching
+2
Manager, IT Governance, Risk & Compliance
Manager, IT Governance, Risk & Compliance

Four Seasons Hotels and Resorts • Toronto

Hybrid
CAD 85,000 - 125,000
Manager, Corporate Financial Reporting
Manager, Corporate Financial Reporting

GFL Environmental Inc. • Vaughan

On-site
CAD 90,000 - 120,000
Health insurance
RRSP matching
Profit sharing