PCI Compliance Analyst

GFL Environmental Inc.$80K — $95K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 3–5 years of experience in information security, risk management, quality assurance, or regulatory compliance.
  • Post-secondary education in technology, auditing, or related field.
  • Strong knowledge of PCI DSS, SOX controls, and regulatory frameworks like NIST and COBIT.
  • Excellent written and verbal communication skills for conveying complex topics to leadership.
  • Experience with industry certifications such as CISA, CISSP, CISM, or familiarity with GDPR.

Responsibilities

  • Test and validate security controls against PCI DSS v4.0 requirements.
  • Review audit documentation and manage remediation of non-compliance findings.
  • Map general controls to the PCI DSS Risk Control Matrix and catalog in-scope environments.
  • Drive automation across GRC functions and update compliance policies.
  • Collaborate with internal teams and auditors, presenting compliance findings to management.

Benefits

  • Comprehensive medical, dental, and vision insurance.
  • Employee Assistance Program, life insurance, and paid time-off.
  • RRSP matching, profit sharing, and competitive wages.
  • Opportunities for growth and continuous learning.
Full Job Description

Ready to elevate your career? GFL is expanding! We are officially hunting for our next IT Compliance & Quality Assurance Specialist (PCI / GRC) in Vaughan—someone ready to bring fresh ideas and grow alongside a dynamic team.

The Role

We are looking for a talented IT Compliance & Quality Assurance Specialist to join our team. In this role, you will play a crucial role in building compliance across the IT enterprise by monitoring, testing, and evaluating internal controls and security reports to ensure alignment with PCI DSS v4.0 and SOX requirements. You will work closely with IT, Security, Product, Finance, and external audit teams to identify non-compliance areas, manage remediation plans, and safeguard sensitive cardholder data across GFL's IT platform. The role reports to the Information Technology GRC Manager.

Key Responsibilities

  • PCI DSS & SOX Control Testing: Test and validate security controls, network diagrams, data flows, and system configurations against PCI DSS v4.0 requirements while balancing SOX Control Self-Assessments.

  • Audit & Remediation Management: Review ROCs/SAQs, manage audit documentation, track identified vulnerabilities or non-compliance findings, and collaborate with IT teams to verify corrective actions.

  • Risk & GRC Integration: Map general controls to the PCI DSS Risk Control Matrix (RCM), catalog in-scope environments, define Key Risk Indicators (KRIs), and integrate PCI requirements into the IT Compliance Control Self-Assessment process.

  • Program Maturation & Automation: Drive automation across the GRC function, update compliance policies and SOPs, and assess new IT projects during planning phases for PCI DSS design and worthiness.

  • Stakeholder & Auditor Collaboration: Partner with internal teams and external auditors through assessments, presenting compliance status, metrics, and QA findings confidently to management and leadership.

What We’re Looking For

  • Experience: 3–5 years of hands-on experience in information security, risk management, quality assurance, or regulatory compliance within a fast-paced environment.

  • Education: Post-secondary education, preferably in technology, auditing, or a related field.

  • Technical Skills: Deep knowledge of PCI DSS (including SAQ requirements for Level 2+ merchants), SOX IT General & Application controls, regulatory frameworks (NIST, COSO, COBIT), cloud computing security, network/data protection controls (NAC, DLP), and API/scanning mechanisms (AVS). Held an Internal Security Assessor (ISA) designation at one point in time.

  • Soft Skills: Excellent written and verbal communication skills with the ability to convey complex technical topics to senior leaders, strong project management skills, and the ability to collaborate across technical and non-technical teams.

  • Bonus Points: Industry credentials such as CISA, CISSP, CISM, AAIA, or PCIP; experience in the Tech Sector; familiarity with data privacy regulations (GDPR, PIPEDA).

What We Offer

Why join us? We believe in taking care of our team. Here is a snapshot of our total rewards you can expect:

  • Health: Comprehensive medical, dental, and vision insurance.

  • Wellness: Employee Assistance Program, life insurance, and paid time-off.

  • Financial: RRSP matching, profit sharing and competitive wages.

  • Culture: Growth opportunities and continuous learning opportunities.

Join us and become part of "Team Green" at GFL Environmental, where your skills and dedication will be valued and rewarded. Apply now for this exciting opportunity!

#GFLTalent



 

We thank you for your interest. Only those selected for an interview will be contacted.


About GFL Environmental Inc.

GFL Environmental Inc. is a Canadian waste management company that provides a wide range of environmental services to customers in Canada and the United States. The company was founded in 2007 and is headquartered in Vaughan, Ontario. GFL Environmental Inc. operates a fleet of more than 10,000 vehicles and employs over 17,000 people. The company's services include solid waste collection, recycling, soil remediation, and liquid waste management. GFL Environmental Inc. is committed to sustainability and has implemented a number of initiatives to reduce its environmental impact.
Learn more about GFL Environmental Inc.
Size
18,000 employees
Market Cap
$12.8 billion
Industry
5 Year Trend
+42.7%
NASDAQ

Similar Jobs

More Jobs at GFL Environmental Inc.

More Information Technology Jobs

Find similar PCI Compliance Analyst jobs: