Avatar

Jack Wozny

BSc, CISSP, CCSP, SSCP, CCSK, CCZT, TAISE, CC, ILO

Biography

Cybersecurity leader and trusted advisor with 15+ years of experience securing complex enterprise environments across legal, finance, and professional services.

I’ve built my career on a foundation of hands-on engineering in identity, cloud, network, endpoint, and security operations, and have progressively taken on greater strategic responsibility: guiding architecture decisions, shaping security policy, advising stakeholders at the executive level, and leading cross-functional security initiatives. At Winston Taylor I operate as a senior subject matter expert and trusted voice on security risk across the firm.

I maintain active affiliations with the DHS Office of Intelligence & Analysis as a Private Sector Partner, InfraGard (FBI), and the Legal Services ISAO, communities that provide actionable threat intelligence and connect private sector security with national infrastructure protection.

Through my private consultancy, I advise a select group of clients on a referral basis, providing vendor-neutral security architecture, risk management, and compliance guidance grounded in real-world engineering experience.

Interests

  • Security
  • Networking
  • Automation

Education

  • BSc in Computer Engineering Technology, 2013

    DeVry University

Experience

 
 
 
 
 

Senior Information Security Engineer

Winston Taylor

Jun 2026 – Present Chicago, IL
 
 
 
 
 

Senior Information Security Engineer

Winston & Strawn, LLP

Nov 2024 – Jun 2026 Chicago, IL
Responsible for a broad range of security technologies across identity, endpoint, network, and cloud domains, including IdP, PAM, EDR, NGFW, SIEM, DLP, and vulnerability scanning solutions. Monitored security events, investigated alerts, conducted threat hunting, and coordinated risk remediation efforts. Developed automation runbooks and integrated security tools using scripting and APIs. Provided risk-based security guidance on IT projects, supported internal security requests, and contributed to the development of security policies, procedures, and hardening standards. Collaborated with cross-functional teams to improve security processes and enhance the firm’s overall security posture.
 
 
 
 
 

Senior Information Security Operations Engineer

Winston & Strawn, LLP

May 2022 – Nov 2024 Chicago, IL
Served as a senior technical resource with expanded ownership of firewall administration, web filtering, identity and access management, and infrastructure operations. Acted as informal liaison to the Information Risk Management department, bridging operational infrastructure with enterprise security and compliance requirements. This cross-departmental visibility into both infrastructure and security functions informed a deliberate transition into a dedicated information security role.
 
 
 
 
 

Information Systems Security Operations Engineer

Winston & Strawn, LLP

Jan 2019 – May 2022 Chicago, IL
Responsible for firewall audit and administration, web filtering administration, and identity and access auditing and automation. Ensured the business met Identity and Access Management (IAM) and network security compliance to fulfill regulatory and client requirements.
 
 
 
 
 

Network Security Engineer

F&I Administration Solutions, LLC

Jun 2018 – Jan 2019 Lombard, IL
Promoted to Network Security Engineer after leading efforts to enhance the organization’s security. Audited network security and firewall configurations, migrated operations to the cloud, and implemented and executed an employee security awareness training plan. Played a key role in strengthening the organization’s overall security posture and ensuring compliance with industry standards.
 
 
 
 
 

Senior System Administrator

F&I Administration Solutions, LLC

Mar 2018 – Jun 2018 Lombard, IL
Responsible for optimizing system and network architecture for SaaS operations. Led initiatives to enhance performance, reliability, and security. Implemented best practices to ensure scalable and robust infrastructure supporting business growth.
 
 
 
 
 

Network Administrator

American Society of Safety Engineers

Jun 2014 – Mar 2018 Park Ridge, IL
Promoted to Network Administrator after demonstrating expertise in network architecture. Managed the entire technical aspect of the business, ranging from system architecture design and deployment to disaster recovery planning and vulnerability assessment. Ensured optimal system performance, maintained network infrastructure, and conducted comprehensive vulnerability assessments to enhance security and reliability.
 
 
 
 
 

IT Support Specialist

American Society of Safety Engineers

Jun 2011 – Jun 2014 Des Plaines, IL
Provided end-user support, network and system administration, and troubleshooting. Diagnosed and resolved technical issues, maintained network infrastructure, and ensured optimal system performance. Delivered high-quality customer service and technical support in fast-paced environments.
 
 
 
 
 

Owner/Consultant, Cybersecurity

Jack Wozny, LLC

Jun 2008 – Present
Founded and lead an independent cybersecurity consultancy providing strategic and hands-on security services to organizations across multiple industries. Delivered end-to-end security engineering, risk reduction, and compliance solutions aligned with business objectives and evolving threat landscapes. I maintain active affiliations with DHS Office of Intelligence & Analysis, InfraGard, and the Legal Services ISAO, giving me access to threat intelligence and sector-specific risk context that informs both my day-to-day work and the guidance I provide to consulting clients. While I maintain strategic partnerships with major technology vendors, my recommendations are always driven by client needs, risk profile, and business objectives.

Recent Posts

Navigating Legal and Security Risks: Managing Access to Former Employees' Email Accounts

Accessing the email accounts of former employees, especially those terminated under contentious circumstances, is fraught with legal …

Governance, Risk, and Compliance References

Quick references to standards covering cybersecurity governance, risk, and compliance

Why Security Questions Are Bad

When it comes to security, using only a password to protect your personal or financial information is no longer enough. Many critical …

Joining Ubuntu Server to AD

Joining linux servers to Microsoft AD for user login and authentication can be a daunting task. The following is the simplest (in my …

Forcing Replication of AD Partitions after Tombstone Lifetime Exceeded

When a domain controller has been offline for more than the specified tombstone lifetime, it is considered bad and will no longer …