CISSP & CISA Certified · Dallas, TX

Jonathan A. Chang

From pharmacy automation to enterprise banking production systems to cybersecurity programs for regulated industries — 7+ years learning exactly how critical systems fail, and making sure they don't.

About

Security-first IT for regulated industries

I'm a senior consultant at a small IT consulting firm specializing in law firms and capital management firms. CISSP-certified with 7+ years across production engineering, cloud infrastructure, and cybersecurity.

From pharmacy automation robots to AWS cloud migrations to SOC 2 compliance programs, my path has always been about making complex systems work reliably and securely.

Security & Compliance

CISSP. SOC 2 Type 1, PCI DSS — zero successful phishing campaigns in 3+ years since deploying Avanan. 1,000+ threats blocked daily, social engineering training, and compliance enforcement

Automation & AI

Built LLM-powered automation handling 50 tickets/day, cutting resolution time 30%. Python, PowerShell, Bash, Docker, CI/CD

Cloud & M365

Deployed Defender + Intune across 1,000+ endpoints — 90% reduction in critical vulnerabilities. AWS, Azure AD, Intune, Conditional Access

Consulting & Leadership

100% client satisfaction across law firms and capital management firms. Mentored 3 engineers, $20K vendor savings, executive-level risk reporting

CISSPCISSPActiveCISACISAActive
AWS Solutions ArchitectEarned
AWS SysOps AdministratorEarned

Selected Work

Things I've built

A few projects that show how I think — from AI governance and automation to the homelab where I break things on purpose.

Firmwide Generative-AI Governance Program

Let regulated firms adopt AI without leaking privileged data

What

Built a generative-AI governance practice from the ground up for legal and financial clients — shadow-AI discovery, acceptable-use policy, and DLP guardrails aligned to the NIST AI RMF.

Why

Staff were already pasting sensitive matter data into public LLMs. There was no policy, no visibility, and real exposure to privilege loss and regulatory risk as firms rushed to adopt AI.

Impact

  • Audited 32,000+ AI requests across 72 devices via DNS-layer telemetry; surfaced 10 unsanctioned shadow-AI tools
  • Authored tailored AI acceptable-use policies placing 500 users under formal governance
  • Deployed prompt/response DLP and SaaS-AI discovery (MagicMirror, Nudge, Microsoft Purview)
  • Presented risk findings to the Risk Committee and drove firmwide policy adoption
GenAI GovernanceNIST AI RMFDLPShadow-AIRisk Reporting

AI Helpdesk Automation & MCP Server

Give technicians instant, context-aware answers — and let the AI act

What

Built AI-powered helpdesk automation: first a GPT app that drafts troubleshooting steps, then a Claude tool-use agent backed by a custom Model Context Protocol (MCP) server wired into RMM tooling.

Why

L1 ticket triage was repetitive and slow. I wanted technicians to get instant, grounded recommendations and to automate routine RMM actions safely.

Impact

  • Original GPT/Python app handled ~50 tickets/day, cutting mean resolution time 30%
  • Built a FastAPI + Claude tool-use proof-of-concept integrating Freshdesk, Atera, and Action1 APIs
  • Developed a custom MCP server exposing RMM automation to the LLM
Claude Tool-UseMCPPythonFastAPILLM Automation

Patch-Ring Automation (Entra → Action1)

Phased, risk-based patching across 1,000+ endpoints — hands-off

What

A daily Azure Automation runbook that syncs Entra ID device-ring groups into Action1, enabling ring-based phased patch deployment and cleaner automated deprovisioning.

Why

Patching a thousand endpoints in a single wave is risky. I needed staged patch rings and wanted device offboarding to happen automatically when a device leaves its Entra group.

Impact

  • Automated patch-ring targeting across 1,000+ endpoints
  • Eliminated manual device-group upkeep between Entra ID and the patch platform
  • Enabled risk-appetite-based SLAs and cleaner automated deprovisioning
Azure AutomationEntra IDAction1PowerShellPatch Management

Self-Hosted Homelab & GRC Sandbox

Where I break things, test security tooling, and run local AI

What

A multi-node Proxmox virtualization lab running 15+ self-hosted services, a segmented VLAN network, ZFS storage, local LLM inference, and a self-hosted GRC platform.

Why

A hands-on environment is how I learn fastest — a place to evaluate security tooling, run local AI without cloud dependency, and practice the GRC frameworks I implement for clients.

Impact

  • 15+ services across LXC/Docker behind a reverse proxy and Cloudflare Tunnel; VLANs, AdGuard DNS filtering, Tailscale mesh VPN
  • ZFS storage on TrueNAS (mirrored vdevs, LSI HBA), UPS monitoring, automated offsite backup
  • Local LLM inference on an RTX 3090 via GPU passthrough
  • Self-hosted Eramba GRC mapping controls to NIST CSF, 800-53, SOC 2, and ISO 27001
ProxmoxTrueNAS / ZFSTailscaleLocal LLMEramba GRC

Why it matters

Security done right is invisible — no breach, no headline, no downtime. For the law firms and capital management firms I work with, a failure isn't just an IT incident. It's attorney-client privilege compromised, client trust broken, regulatory standing threatened. And as these firms race to adopt AI, the attack surface only widens — securing how these tools touch privileged data is the next front. Understanding what's actually at stake is what makes this work serious.

Journey

From pharmacy robots to cybersecurity

A non-linear path through healthcare, production engineering, cloud infrastructure, and IT security.

Sept 2025 - Present

Program Manager, Cybersecurity

IT Consulting Firm (Legal & Financial Sector)

Frisco, TX

Architecting and enforcing security policies for enterprise clients in the legal industry. Leading operational stability programs across 1,000+ endpoints and owning incident response, compliance, vendor management, and the secure adoption of AI tooling.

  • Resolved containable incidents 83% faster — full-day outages down to under 2 hours
  • Enabled 24/7 risky sign-in alerting, preventing 6+ account takeovers in 6 months
  • Leading SOC 2 Type 1 and PCI DSS compliance programs
  • Established AI usage guardrails to protect privileged client data as firms adopt LLM tools
  • Managing third-party security vendor relationships (MDR, BCDR, EDR)
CybersecurityAI SecurityComplianceIncident ResponseSOC 2PCI DSS

Mar 2023 - Sept 2025

Solutions Engineer (DevOps & Automation)

IT Consulting Firm (Legal & Financial Sector)

Frisco, TX

Senior consultant delivering IT support, security hardening, and automation for law firms and capital management firms. Built tooling, mentored junior engineers, and drove infrastructure modernization across multiple client environments.

  • Built GPT-based automation app handling ~50 tickets/day, improving resolution time 30%
  • Deployed Microsoft Defender + Intune across 1,000+ endpoints, reducing critical vulnerabilities 90%
  • Engineered secure LAN/WAN infrastructure across 10 sites supporting 250 users
  • Mentored 3 junior engineers from green hires to handling L2.5 tickets independently
PythonM365DevOpsNetworkingMentorship

Sept 2020 - May 2022

Production Support Specialist (Tier 4)

Capital One Financial Corporation

Plano, TX

Capital One Financial Corporation

Led major incident management for critical banking systems, coordinating cross-functional teams to minimize downtime for tens of thousands of users.

  • Led 3-5 major incident bridges weekly for high-stakes production issues
  • Created runbooks reducing MTTR by 40%
  • Implemented AWS CloudWatch monitoring, preventing 6-8 downtime incidents per quarter
  • Built Splunk dashboards reducing failure identification time 50%
Incident ManagementAWSSplunkProduction Support

Aug 2020 - May 2024

B.S. Information Technology & Systems

The University of Texas at Dallas

Richardson, TX

The University of Texas at Dallas

Studied IT & Systems under the Naveen Jindal School of Management. Coursework in AI/Machine Learning with Python and Oracle SQL Database Design.

  • Board Member-Secretary, Real Estate Club at UTD
  • Student Leader, Epic Movement at UTD
AI/MLSQLIT Management

Feb 2019 - Sept 2020

Production Analyst

Verisk Analytics (S&P 500)

College Station, TX

Verisk Analytics (S&P 500)

Maintained 99.9% uptime for 20+ VMware Horizon application servers. Automated operational tasks, containerized applications for AWS migration, and built secure ETL pipelines processing sensitive government data.

  • Automated 3 manual processes with Docker & Bash, saving 4+ hours weekly
  • Containerized internal applications for AWS cloud migration
  • Built secure ETL pipelines processing PII data from 15 legacy government systems
DockerVMwareAWSETLBash

Jan 2018

Director of Medicine - Global Medical Brigades

Texas A&M University

Esteli, Nicaragua

Texas A&M University

Led medical efforts for a brigade serving communities in rural Nicaragua with healthcare and sanitary education. Chosen by peers to direct the medical program.

HumanitarianHealthcareLeadership

Aug 2017 - Dec 2018

Genetics (Pre-Med, 74 credit hours)

Texas A&M University

College Station, TX

Texas A&M University

Studied Genetics as a pre-med hopeful before pivoting to technology - a career change that shaped my entire professional trajectory.

GeneticsPre-MedSTEM

Feb 2017 - Feb 2020

Certified Pharmacy Technician

MChest Pharmacy

College Station, TX

MChest Pharmacy

Supervised mission-critical automation robots processing 2,500 prescriptions daily. Engineered a process improvement recognized by the COO and scaled enterprise-wide.

  • Maintained 95% uptime on automation robots handling 70% of daily volume
  • Created efficiency improvement saving 10 seconds per order, adopted at multiple branches
AutomationPharmacyProcess Improvement