PCI Compliance Analyst

Posted 6 Days Ago
Be an Early Applicant
Vaughan, ON, CAN
In-Office
Mid level
Greentech • Other • Professional Services • Industrial
The Role
Test and validate PCI DSS and SOX IT controls, review audit documentation, manage remediation plans, map controls to risk matrices, and monitor compliance findings. The role supports GRC automation, policy and SOP updates, PCI assessments for new IT projects, and collaboration with IT, Security, Finance, Product, auditors, and leadership. Responsibilities include evaluating network diagrams, data flows, configurations, vulnerabilities, KRIs, and sensitive cardholder data protections.
Summary Generated by Built In


 

Ready to elevate your career? GFL is expanding! We are officially hunting for our next IT Compliance & Quality Assurance Specialist (PCI / GRC) in Vaughan—someone ready to bring fresh ideas and grow alongside a dynamic team.

About Us

GFL is one of the largest diversified environmental services companies in North America, providing comprehensive solid waste management services from its platform of facilities throughout Canada and 18 U.S. states. Recognized by our signature fleet of bright green trucks and equipment, we offer a wide range of environmental and industrial services to businesses, communities and households, providing a consolidated and sophisticated approach to meeting our customers’ needs. One of the keys to our success lies in the diversity of our services and our ability to deliver robust integrated solutions, all from a single efficient company. We believe that, by providing safe, accessible and cost-effective solutions, we encourage greater environmental responsibility and allow our customers and the communities we serve to be Green for Life.

The Role

We are looking for a talented IT Compliance & Quality Assurance Specialist to join our team. In this role, you will play a crucial role in building compliance across the IT enterprise by monitoring, testing, and evaluating internal controls and security reports to ensure alignment with PCI DSS v4.0 and SOX requirements. You will work closely with IT, Security, Product, Finance, and external audit teams to identify non-compliance areas, manage remediation plans, and safeguard sensitive cardholder data across GFL's IT platform. The role reports to the Information Technology GRC Manager.

Key Responsibilities

  • PCI DSS & SOX Control Testing: Test and validate security controls, network diagrams, data flows, and system configurations against PCI DSS v4.0 requirements while balancing SOX Control Self-Assessments.

  • Audit & Remediation Management: Review ROCs/SAQs, manage audit documentation, track identified vulnerabilities or non-compliance findings, and collaborate with IT teams to verify corrective actions.

  • Risk & GRC Integration: Map general controls to the PCI DSS Risk Control Matrix (RCM), catalog in-scope environments, define Key Risk Indicators (KRIs), and integrate PCI requirements into the IT Compliance Control Self-Assessment process.

  • Program Maturation & Automation: Drive automation across the GRC function, update compliance policies and SOPs, and assess new IT projects during planning phases for PCI DSS design and worthiness.

  • Stakeholder & Auditor Collaboration: Partner with internal teams and external auditors through assessments, presenting compliance status, metrics, and QA findings confidently to management and leadership.

What We’re Looking For

  • Experience: 3–5 years of hands-on experience in information security, risk management, quality assurance, or regulatory compliance within a fast-paced environment.

  • Education: Post-secondary education, preferably in technology, auditing, or a related field.

  • Technical Skills: Deep knowledge of PCI DSS (including SAQ requirements for Level 2+ merchants), SOX IT General & Application controls, regulatory frameworks (NIST, COSO, COBIT), cloud computing security, network/data protection controls (NAC, DLP), and API/scanning mechanisms (AVS). Held an Internal Security Assessor (ISA) designation at one point in time.

  • Soft Skills: Excellent written and verbal communication skills with the ability to convey complex technical topics to senior leaders, strong project management skills, and the ability to collaborate across technical and non-technical teams.

  • Bonus Points: Industry credentials such as CISA, CISSP, CISM, AAIA, or PCIP; experience in the Tech Sector; familiarity with data privacy regulations (GDPR, PIPEDA).

What We Offer

Why join us? We believe in taking care of our team. Here is a snapshot of our total rewards you can expect:

  • Health: Comprehensive medical, dental, and vision insurance.

  • Wellness: Employee Assistance Program, life insurance, and paid time-off.

  • Financial: RRSP matching, profit sharing and competitive wages.

  • Culture: Growth opportunities and continuous learning opportunities.

Join us and become part of "Team Green" at GFL Environmental, where your skills and dedication will be valued and rewarded. Apply now for this exciting opportunity!

#GFLTalent


We thank you for your interest. Only those selected for an interview will be contacted.


GFL is committed to equal opportunity for all, without regard to race, religion, color, national origin, citizenship, sex, sexual orientation, gender identity, age, veteran status, disability, genetic information, or any other protected characteristic. If you are interested in applying for employment and need special assistance or an accommodation to apply for a posted position, please contact [email protected]
Please note that GFL does not provide visa sponsorship
 for this position. Valid work authorization in the country where the job is located is required. Successful candidates will be required to provide valid documentation confirming their eligibility to work in the country where the job is located prior to their start date.


This hiring process may utilize machine-based systems to assist in screening and assessing applicants. Final selection decisions are made by our recruitment team.


Skills Required

  • 3-5 years of hands-on experience in information security, risk management, quality assurance, or regulatory compliance
  • Post-secondary education, preferably in technology, auditing, or a related field
  • Deep knowledge of PCI DSS, including SAQ requirements for Level 2+ merchants
  • Knowledge of SOX IT General and Application controls
  • Knowledge of NIST, COSO, and COBIT frameworks
  • Knowledge of cloud computing security and network/data protection controls, including NAC and DLP
  • Knowledge of API/scanning mechanisms, including AVS
  • Previously held an Internal Security Assessor designation
  • Excellent written and verbal communication skills
  • Strong project management and cross-functional collaboration skills
  • CISA, CISSP, CISM, AAIA, or PCIP credentials
  • Experience in the technology sector
  • Familiarity with GDPR and PIPEDA
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
20,000 Employees
Year Founded: 2007

What We Do

GFL Environmental Inc. is a leading North American provider of diversified environmental waste management and infrastructure development solutions. It is the fourth largest diversified environmental services company in North America, providing comprehensive solid waste management, liquid waste management, and soil remediation services across Canada and the United States to over 4 million households and 135,000 industrial, commercial, and institutional customers.

Similar Jobs

Enverus Logo Enverus

Manager, Power Markets - 26232DD

Big Data • Information Technology • Software • Analytics • Energy
In-Office or Remote
2 Locations
1800 Employees

CrowdStrike Logo CrowdStrike

Sr. Competitive Intelligence Analyst III (Remote)

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote or Hybrid
5 Locations
11000 Employees
145K-225K Annually

Halter Logo Halter

'The Returners' Talent Pool

Greentech • Hardware • Internet of Things • Machine Learning • Software • Business Intelligence • Agriculture
In-Office or Remote
8 Locations
350 Employees

Tapestry - Coach and Kate Spade Logo Tapestry - Coach and Kate Spade

Sales Associate III-10

eCommerce • Fashion • Retail • Sales • Wearables • Design
Hybrid
Toronto, ON, CAN
16000 Employees
18-22 Hourly

Similar Companies Hiring

Quantum Rise Thumbnail
Software • Professional Services • Natural Language Processing • Machine Learning • Consulting • Automation • Artificial Intelligence
Chicago, Illinois
20 Employees
Rosendin Thumbnail
Other • Manufacturing
San Jose, CA
6219 Employees
Amalgamated Sugar Thumbnail
Food • Greentech • Agriculture • Industrial • Manufacturing
Boise, Idaho
768 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account