Taylor Craig, Information Security Professional

Supporting the needs of the business through effective security measures.

With nearly a decade of experience in cybersecurity—spanning both blue team defense and red team offense—I bring a unique perspective and deep understanding to every team and client engagement.

Professional Experience

Information Security Engineer <> Digital Monitoring Products

April 2026 – October 2026

  • Own the vulnerability management process from identification to remediation.
  • Lead incident response from detection to postmortem and lessons learned.
  • Proactively identifying over-looked security configurations and taking corrective actions.
  • Using tools that real world threat actors utilize to proactively tune alert and response procedures.
  • Configuring, testing, and auditing all GPOs, Confitional Access Policies, and group memberships in Active Directory and Entra ID.
  • Curate and lead security education and best-practices for all employees.

Penetration Tester <> NetWorks Group

October 2022 – August 2025

  • Engaged with clients across a variety of industries including lead Penetration Tester for over 30 projects.
  • Testing domains included Windows Active Directory, Azure/Entra ID, AWS, Web Application, Wireless Testing, Social Engineering, and Physical On-Site Testing.
  • Achieved nearly 100% success rate in identifying gaps in physical security and gaining access to secure facilities while maintaining scope and professionalism.
  • Written and proofread hundreds of full-scope penetration testing reports ensuring professional, clear, and actionable language throughout.
  • Contributed and authored several technical blog posts for the company blog. Many can be found linked on this site’s blog.
  • Maintained up-to-date and professional communication with clients prior, during, and post engagements. Providing a reliable source as a subject matter expert for clients as they work through mitigations and remediation for any findings.
  • Led clients through Purple Team Exercises providing detailed insight into the ethical hacking mindset and assisting Blue Teams with recommendations on alert creation and tuning.
  • Engage with clients to assess PCI DSS compliance including testing and verifying CDE environmental isolation.
  • Leveraged AI for countless social engineering campaigns including vishing and phishing through both automated and manual techniques.
  • Presented technical findings to both technical and non-technical stakeholders including board of directors and executives in a clear and understandable way to ensure understanding of business risk.

Cyber Security Analyst <> Great Southern Bank

October 2018 – October 2022

  • Active threat hunting and implementation of mitigations leveraging LogRhythm and Splunk SIEM solutions and Cisco NetFlow solutions such as Secure Network Analytics (formally Stealthwatch).
  • Oversees endpoint vulnerability management (Rapid7) as a SME and liaison working closely with relevant stockholders and system owners. Providing insight and risk management for specific identified vulnerabilities and remediation recommendations.
  • Upgrading enterprise servers/VM clusters. Including all relevant solutions and applications under the ownership of the IT Security department.
  • Review application whitelist requests from users to determine safety and legitimacy using Carbon Black (formally Bit9).

IT Support Specialist <> Mid Missouri Bank

December 2017 – September 2018

Roles

Cyber Security Advisory Committee Member

Ozarks Technical Community College

Webmaster & Writer

taylorcraig.com

Brazilian Jiu-Jitsu Instructor (Black Belt)

Springfield BJJ

Certification

Certified Information Systems Security Professional (CISSP)

(ISC)2 – April 2026

Credential ID: 702208

Certified Professional Penetration Tester (eCPPT)

INE (Formally eLearn Security) – April 2021

Credential ID: 9795365