Craig Grace — Cybersecurity & IT

Welcome.

Thanks for finding your way to my personal site. I'm Craig, and I've been passionate about learning and building my knowledge in cybersecurity for several years now. That curiosity is what led me to pursue a second bachelor's degree in Information Assurance & Cyber Defense at Northern Michigan University — I wanted to understand how systems actually fail, and how to design and defend against that failure before it happens.

Two areas hold my attention right now. The first is cloud security — so much of modern infrastructure now lives in shared, externally-managed environments where the perimeter isn't a wall anymore, it's a set of permissions and configurations, and getting those wrong is how breaches happen. The second is AI automation risk — the same tools accelerating security work are introducing attack surfaces we're only beginning to understand, and a poorly-scoped AI agent can become as much of a liability as an unpatched server.

My coursework spans database systems and secure data architecture, cloud security fundamentals, incident response, and network defense — each one another angle on the same question: where does trust break down, and how do you catch it early? Beyond my background below, this site also holds notes, projects, and tools I've built while learning — worth a look if you're in the field too.

Portrait of Craig Grace

Security operations

A SOC analyst's job is pattern recognition under time pressure: watch the alerts a SIEM surfaces, work out which ones matter, and follow a defined process to contain and document what's actually happening. It's less about heroics and more about not missing the quiet signal in a noisy feed.

The gap that actually matters isn't "an alert fired" — it's between that and "here's what happened and what we did about it." A tool can surface an anomaly; only a process turns that anomaly into a documented, defensible response. That's why the boring parts of SOC work — clear escalation paths, consistent documentation, knowing which playbook applies before you need it — end up mattering more than any single piece of threat intelligence. Speed without structure just means panicking faster. I've written more on what that process actually looks like in the incident response lifecycle.

Networking

Almost everything in security eventually comes back to how traffic actually moves — addressing, routing, what a firewall is really deciding when it drops a packet, what an IDS/IPS is watching for versus what it acts on.

Most security problems are network problems wearing a different hat — a "compromised account" is really a set of connections that shouldn't have been possible in the first place. Understanding how traffic is supposed to move is what makes it obvious when it isn't. That's the real value of network fundamentals: not memorizing port numbers, but building the instinct to look at a topology and immediately spot where trust is assumed instead of enforced. Reading actual packets is where that instinct gets tested.

Cloud

More infrastructure lives in someone else's data center every year, which means more of the job is understanding shared responsibility: what AWS secures, what you secure, and where the seams are.

Shared responsibility sounds simple until something goes wrong, and then it becomes the whole question: was this a provider failure or a misconfigured bucket someone left open? Most cloud breaches trace back to the second kind — not a flaw in the platform, but a permission that was broader than it needed to be. Treating the cloud as "someone else's problem" is exactly the assumption that causes the incident. It's also the thinking behind zero trust: rather than assuming anything inside a network boundary is safe, every request gets verified on its own merits, every time, regardless of where it's coming from. In an environment with no real perimeter left, that's less a new idea than an honest description of how things already work.

Risk & governance

A vulnerability isn't automatically a priority — risk assessment is the discipline of deciding what actually needs fixing first, and being able to explain that decision to people who don't speak in CVSS scores.

A hundred-page vulnerability scan is useless if nobody can tell which ten items on it actually matter. Good risk assessment isn't about finding more problems — scanners already do that — it's about triage: separating theoretical exposure from what a realistic attacker would actually exploit, and then explaining that distinction clearly enough that a non-technical decision-maker can act on it. The technical skill and the communication skill aren't separate parts of the job; a risk assessment nobody understands doesn't reduce any risk at all. The CIA triad is usually the fastest way to explain what's actually at stake.

Teaching & training

Security awareness training is only as good as the instructional design behind it — most people don't ignore phishing warnings because they're careless, they ignore them because the training was forgettable.

Most breaches don't start with a brilliant exploit — they start with someone clicking a link, reusing a password, or plugging in a USB drive they found in a parking lot. No firewall fixes that. The only real defense is people who've actually internalized why it matters, and that only happens through training that's designed well, not just delivered. A slide deck people click through once a year changes nothing; a habit changes everything. That's the gap good instructional design is built to close, and it's why I think security awareness deserves the same rigor as any technical control — because the human layer is the one attackers target first, precisely because it's usually the least defended.

Education & credentials

B.S., Information Assurance & Cyber Defense

Northern Michigan University · expected December 2026 · GPA 3.82

B.Sc., Sociology, minors in Psychology & Criminology

University of the West Indies

M.Sc., Sociology of Development

University of the West Indies

Certifications

CCNA AWS Certified Cloud Practitioner

Affiliations & honors

Member, NMU Student Cybersecurity Association
Undergraduate Research Fellowship, 2026–2027

Get in touch

If any of the above sounds like a role you're hiring for, or you just want to talk shop about cloud security, AI risk, or where the two collide, I'd like to hear from you.

Email Craig Grace

gracecraig.1q@gmail.com