Hiring.Camp

PCI Compliance Analyst

Gflenv

·

Today

Location
200 Apple Mill Rd 700,Vaughan,ON, Canada
Type
Full-time
Department
Legal
Visa
Not sponsored
Source
Workday

Description



 

Ready to elevate your career? GFL is expanding! We are officially hunting for our next IT Compliance & Quality Assurance Specialist (PCI / GRC) in Vaughan—someone ready to bring fresh ideas and grow alongside a dynamic team.

About Us

GFL is one of the largest diversified environmental services companies in North America, providing comprehensive solid waste management services from its platform of facilities throughout Canada and 18 U.S. states. Recognized by our signature fleet of bright green trucks and equipment, we offer a wide range of environmental and industrial services to businesses, communities and households, providing a consolidated and sophisticated approach to meeting our customers’ needs. One of the keys to our success lies in the diversity of our services and our ability to deliver robust integrated solutions, all from a single efficient company. We believe that, by providing safe, accessible and cost-effective solutions, we encourage greater environmental responsibility and allow our customers and the communities we serve to be Green for Life.

The Role

We are looking for a talented IT Compliance & Quality Assurance Specialist to join our team. In this role, you will play a crucial role in building compliance across the IT enterprise by monitoring, testing, and evaluating internal controls and security reports to ensure alignment with PCI DSS v4.0 and SOX requirements. You will work closely with IT, Security, Product, Finance, and external audit teams to identify non-compliance areas, manage remediation plans, and safeguard sensitive cardholder data across GFL's IT platform. The role reports to the Information Technology GRC Manager.

Key Responsibilities

  • PCI DSS & SOX Control Testing: Test and validate security controls, network diagrams, data flows, and system configurations against PCI DSS v4.0 requirements while balancing SOX Control Self-Assessments.

  • Audit & Remediation Management: Review ROCs/SAQs, manage audit documentation, track identified vulnerabilities or non-compliance findings, and collaborate with IT teams to verify corrective actions.

  • Risk & GRC Integration: Map general controls to the PCI DSS Risk Control Matrix (RCM), catalog in-scope environments, define Key Risk Indicators (KRIs), and integrate PCI requirements into the IT Compliance Control Self-Assessment process.

  • Program Maturation & Automation: Drive automation across the GRC function, update compliance policies and SOPs, and assess new IT projects during planning phases for PCI DSS design and worthiness.

  • Stakeholder & Auditor Collaboration: Partner with internal teams and external auditors through assessments, presenting compliance status, metrics, and QA findings confidently to management and leadership.

What We’re Looking For

  • Experience: 3–5 years of hands-on experience in information security, risk management, quality assurance, or regulatory compliance within a fast-paced environment.

  • Education: Post-secondary education, preferably in technology, auditing, or a related field.

  • Technical Skills: Deep knowledge of PCI DSS (including SAQ requirements for Level 2+ merchants), SOX IT General & Application controls, regulatory frameworks (NIST, COSO, COBIT), cloud computing security, network/data protection controls (NAC, DLP), and API/scanning mechanisms (AVS). Held an Internal Security Assessor (ISA) designation at one point in time.

  • Soft Skills: Excellent written and verbal communication skills with the ability to convey complex technical topics to senior leaders, strong project management skills, and the ability to collaborate across technical and non-technical teams.

  • Bonus Points: Industry credentials such as CISA, CISSP, CISM, AAIA, or PCIP; experience in the Tech Sector; familiarity with data privacy regulations (GDPR, PIPEDA).

What We Offer

Why join us? We believe in taking care of our team. Here is a snapshot of our total rewards you can expect:

  • Health: Comprehensive medical, dental, and vision insurance.

  • Wellness: Employee Assistance Program, life insurance, and paid time-off.

  • Financial: RRSP matching, profit sharing and competitive wages.

  • Culture: Growth opportunities and continuous learning opportunities.

Join us and become part of "Team Green" at GFL Environmental, where your skills and dedication will be valued and rewarded. Apply now for this exciting opportunity!

#GFLTalent



 

We thank you for your interest. Only those selected for an interview will be contacted.


GFL is committed to equal opportunity for all, without regard to race, religion, color, national origin, citizenship, sex, sexual orientation, gender identity, age, veteran status, disability, genetic information, or any other protected characteristic. If you are interested in applying for employment and need special assistance or an accommodation to apply for a posted position, please contact [email protected]

Please note that GFL does not provide visa sponsorship
 for this position. Valid work authorization in the country where the job is located is required. Successful candidates will be required to provide valid documentation confirming their eligibility to work in the country where the job is located prior to their start date.


This hiring process may utilize machine-based systems to assist in screening and assessing applicants. Final selection decisions are made by our recruitment team.


 

Skills

SOXRisk ManagementComplianceProject ManagementGDPRCISSP

Similar Jobs

4

cybersecurity analyst senior, PCI compliance

Starbucks · Seattle, WA,US, US · Hybrid

3 weeks ago

Sr. Security Compliance Analyst -PCI DSS & U.S. Fed

Entrust is an innovative leader · United States - Shakopee, MN (GHQ), United States of America · Remote

1 month ago

Sr. Security Compliance Analyst - PCI DSS & SOC 2  (East Coast)

Entrust is an innovative leader · United States - Field, United States of America · Hybrid

1 month ago

PCI Compliance Analyst II

Global Payments · GSC Vertis North, Philippines · Hybrid

1 month ago