Taylor Craig, Information Security Professional
Supporting the needs of the business through effective security measures.
With nearly a decade of experience in cybersecurity—spanning both blue team defense and red team offense—I bring a unique perspective and deep understanding to every team and client engagement.
Professional Experience
Information Security Engineer <> Digital Monitoring Products
April 2026 – October 2026
- Own the vulnerability management process from identification to remediation.
- Lead incident response from detection to postmortem and lessons learned.
- Proactively identifying over-looked security configurations and taking corrective actions.
- Using tools that real world threat actors utilize to proactively tune alert and response procedures.
- Configuring, testing, and auditing all GPOs, Confitional Access Policies, and group memberships in Active Directory and Entra ID.
- Curate and lead security education and best-practices for all employees.
Penetration Tester <> NetWorks Group
October 2022 – August 2025
- Engaged with clients across a variety of industries including lead Penetration Tester for over 30 projects.
- Testing domains included Windows Active Directory, Azure/Entra ID, AWS, Web Application, Wireless Testing, Social Engineering, and Physical On-Site Testing.
- Achieved nearly 100% success rate in identifying gaps in physical security and gaining access to secure facilities while maintaining scope and professionalism.
- Written and proofread hundreds of full-scope penetration testing reports ensuring professional, clear, and actionable language throughout.
- Contributed and authored several technical blog posts for the company blog. Many can be found linked on this site’s blog.
- Maintained up-to-date and professional communication with clients prior, during, and post engagements. Providing a reliable source as a subject matter expert for clients as they work through mitigations and remediation for any findings.
- Led clients through Purple Team Exercises providing detailed insight into the ethical hacking mindset and assisting Blue Teams with recommendations on alert creation and tuning.
- Engage with clients to assess PCI DSS compliance including testing and verifying CDE environmental isolation.
- Leveraged AI for countless social engineering campaigns including vishing and phishing through both automated and manual techniques.
- Presented technical findings to both technical and non-technical stakeholders including board of directors and executives in a clear and understandable way to ensure understanding of business risk.
Cyber Security Analyst <> Great Southern Bank
October 2018 – October 2022
- Active threat hunting and implementation of mitigations leveraging LogRhythm and Splunk SIEM solutions and Cisco NetFlow solutions such as Secure Network Analytics (formally Stealthwatch).
- Oversees endpoint vulnerability management (Rapid7) as a SME and liaison working closely with relevant stockholders and system owners. Providing insight and risk management for specific identified vulnerabilities and remediation recommendations.
- Upgrading enterprise servers/VM clusters. Including all relevant solutions and applications under the ownership of the IT Security department.
- Review application whitelist requests from users to determine safety and legitimacy using Carbon Black (formally Bit9).
IT Support Specialist <> Mid Missouri Bank
December 2017 – September 2018
Roles
Cyber Security Advisory Committee Member
Ozarks Technical Community College
Webmaster & Writer
taylorcraig.com
Brazilian Jiu-Jitsu Instructor (Black Belt)
Springfield BJJ
Certification
Certified Information Systems Security Professional (CISSP)
(ISC)2 – April 2026
Credential ID: 702208
Certified Professional Penetration Tester (eCPPT)
INE (Formally eLearn Security) – April 2021
Credential ID: 9795365