PCI Compliance Analyst

GFL Environmental Inc.Vaughan, ON
Onsite

About The Position

GFL is expanding and seeking an IT Compliance & Quality Assurance Specialist (PCI / GRC) to join their dynamic team in Vaughan. GFL is a leading diversified environmental services company in North America, offering comprehensive solid waste management and industrial services across Canada and the U.S. They are known for their distinctive green fleet and commitment to providing safe, accessible, and cost-effective environmental solutions, aiming to promote environmental responsibility and a 'Green for Life' approach for their customers and communities.

Requirements

  • 3–5 years of hands-on experience in information security, risk management, quality assurance, or regulatory compliance within a fast-paced environment.
  • Post-secondary education, preferably in technology, auditing, or a related field.
  • Deep knowledge of PCI DSS (including SAQ requirements for Level 2+ merchants), SOX IT General & Application controls, regulatory frameworks (NIST, COSO, COBIT), cloud computing security, network/data protection controls (NAC, DLP), and API/scanning mechanisms (AVS).
  • Held an Internal Security Assessor (ISA) designation at one point in time.
  • Excellent written and verbal communication skills with the ability to convey complex technical topics to senior leaders.
  • Strong project management skills.
  • Ability to collaborate across technical and non-technical teams.
  • Valid work authorization in the country where the job is located is required.
  • Successful candidates will be required to provide valid documentation confirming their eligibility to work in the country where the job is located prior to their start date.

Nice To Haves

  • Industry credentials such as CISA, CISSP, CISM, AAIA, or PCIP
  • Experience in the Tech Sector
  • Familiarity with data privacy regulations (GDPR, PIPEDA)

Responsibilities

  • Test and validate security controls, network diagrams, data flows, and system configurations against PCI DSS v4.0 requirements while balancing SOX Control Self-Assessments.
  • Review ROCs/SAQs, manage audit documentation, track identified vulnerabilities or non-compliance findings, and collaborate with IT teams to verify corrective actions.
  • Map general controls to the PCI DSS Risk Control Matrix (RCM), catalog in-scope environments, define Key Risk Indicators (KRIs), and integrate PCI requirements into the IT Compliance Control Self-Assessment process.
  • Drive automation across the GRC function, update compliance policies and SOPs, and assess new IT projects during planning phases for PCI DSS design and worthiness.
  • Partner with internal teams and external auditors through assessments, presenting compliance status, metrics, and QA findings confidently to management and leadership.

Benefits

  • Comprehensive medical, dental, and vision insurance.
  • Employee Assistance Program
  • Life insurance
  • Paid time-off
  • RRSP matching
  • Profit sharing
  • Competitive wages
  • Growth opportunities
  • Continuous learning opportunities
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service