Curiosity,
put to work.

Hi, I’m Joel. I care about how systems work,
and how to make them work better.

Explore my work
Headshot of Joel Chan outdoors
Participants collaborating at a cyber defense competition
April 2022–present

Cyber defense competitions

A practical environment for defending networks under pressure: securing services, investigating intrusions, and keeping systems usable for the people who depend on them.

Since 2022Learning through live defense
My contribution
I helped implement firewalls, remove planted backdoors and insecure configurations, apply least-privilege Group Policy, and monitor activity with Wazuh. I also documented systems and intrusions and contributed to team strategy.
What I learned
Security and usability have to work together. I created step-by-step, screenshot-supported instructions for remote access and a competition website, learning to make technical systems understandable to their users.
Resources
Wazuh SIEM, firewalls, Group Policy, Windows and Linux security, and team documentation.
Outcome
Hands-on defensive security and clear documentation in a collaborative competition setting.
John Deere · Professional work

AWS automation migration

An EC2 termination automation workflow needed to run beyond its existing Lambda runtime limit. I migrated the automation to ECS and managed the infrastructure with Terraform.

Lambda → ECSInfrastructure managed with Terraform
My contribution
I migrated the existing AWS automation from Lambda to ECS using Terraform.
What I learned
I learned when to choose Lambda or ECS for automation. Lambda was simpler to deploy, but its execution time limit made ECS a better fit for our long-running workflow. I also learned how Terraform defines and deploys the infrastructure, allowing me to manage these automations through code instead of configuring them in the AWS console.
Resources
AWS Lambda, ECS, EC2, Terraform, and the existing automation workflow.
Outcome
Removed the runtime limitation and improved the reliability of the workflow.
John Deere · Professional work

Vulnerability association automation

Unassociated vulnerability findings make remediation harder to route. I developed a script to match Qualys findings with device records in the ServiceNow configuration management database.

2,000+Findings connected to device records
My contribution
I engineered the association script, connecting previously unassociated findings to their device records.
What I learned
I learned how ServiceNow can integrate with vulnerability platforms to connect findings to devices and devices to the teams responsible for them. Understanding these relationships showed me how accurate device and ownership information helps route remediation work to the right people and supports timely remediation.
Resources
Qualys findings, ServiceNow CMDB device records, and scripting automation.
Outcome
Matched more than 2,000 unassociated findings to device records.
Senior design · Project 42

Modular robotic platform

Our team is planning a modular robotic platform with two-way video and audio. The initial brief combines telepresence with expandable hardware modules, including a grabber and a modular enclosure.

Two-wayVideo & audio · Planned
My contribution
My responsibility is developing the custom video-calling solution for communication between two devices on the platform.
What I learned
I learned how to understand different users and use their needs to guide product decisions. I also learned how to implement a custom video-calling solution that enables communication between two devices.
Big-picture contribution
Intended contribution: enable remote communication through a platform that can grow into a modular robotics system.
Initial project brief (Word document)

About
me.

I’m pursuing a full-time cybersecurity role where I can use automation to make security operations more effective. I want to keep learning across cybersecurity while building practical solutions that account for the people who use them.

At Iowa State, I’m studying Cyber Security Engineering and regularly attending the Hacking and Cybersecurity Club. I learn through hands-on projects, collaboration, and asking how things can work better.

Iowa State University

B.S. Cyber Security Engineering
Expected graduation · May 2027
GPA · 3.7

John Deere

Part Time Student · Vulnerability Management
April 2025–present

I work on vulnerability management, remediation coordination, and automation. My work includes connecting findings with devices and helping IT teams address vulnerabilities.

During my time at John Deere, I learned how organizations use AWS to automate repetitive work. I learned to run automations with Lambda and ECS and use CloudWatch to monitor and review them.

I also learned Agile project management practices, including sprints, daily Scrum meetings, retrospectives, and refinement.

800+Incorrectly open findings resolved
76 → 90%Nutanix scan coverage
AWSTerraformQualysServiceNowWazuhWindows & LinuxActive DirectoryGroup PolicySQLAutomation

TestOut certifications: PC Pro · Security Pro · Network Pro · Routing and Switching Pro · Ethical Hacker Pro · Server Pro: Core.

Reflections
& writing.

Personal reflections on learning,
engineering, and responsibility.

Cumulative reflection

Learning, teamwork, and the engineer I’m becoming.

Read PDF

General Education Reflection

How a broader education shapes my engineering perspective.

Read PDF

Engineering ethics

CPRE / EE 394 ethics paper.

Coming soon
Download my résumé (PDF, opens in a new tab)