Securitythatholdsup
underoutsidereview.
Cybersecurity program manager with a decade inside connected and autonomous vehicle systems. Rebuilt governance on a U.S. Navy marine engine cybersecurity program at Caterpillar, cutting documentation cycle time about 40% and lifting risk detection about 30%. Owned the POA&M from control gap to closure. CISSP. PMP. SAFe 6.
A control is a claim.
Evidence is the proof.
Security programs rarely fail on the controls themselves. They fail at the handoff between the people who build a system and the people who have to certify it. That handoff is my job: choosing the controls that actually apply, planning the evidence before anyone asks for it, tracking every gap to closure, and keeping engineering, internal security and assessors aligned until the review is done.
From control gap to closure.
The lifecycle I ran on the U.S. Navy marine engine cybersecurity program at Caterpillar, where I owned the POA&M end to end. Step through it to follow one item from the day a gap is found to the day an assessor accepts it.
Control selection
Scoping starts with the obligation. On the Navy program I drove NIST 800-171 and CMMC readiness and government cloud authorization prep, beginning with control selection so every later step measured against the right baseline.
Program result: documentation cycle time down about 40%, risk detection up about 30%.
Stage content describes my role and the artifacts I owned. It is not a record of any specific finding on the program.
A vehicle technologist, now securing the systems I used to build.
My route into security ran the opposite way from most. Before governance, there was engineering: installing telematics hardware, testing ECUs on the bench, migrating fleet platforms and assessing over-the-air update pipelines for signing and tamper exposure. That background is why my control reviews reach the ECU, not just the policy binder.
At Caterpillar, on a U.S. Navy marine engine cybersecurity program in the company's defense business, I rebuilt the governance and documentation architecture, authored the security plan documentation, and served as primary liaison to federal oversight stakeholders and external certification bodies including ABS.
Through my independent practice I have delivered security governance for Visa Europe, Samsara AI and Lineage Logistics, mapping policies, standards and control libraries to each client's obligations, including GDPR, and compliance readiness for the City of Seattle against NIST 800-171.
Today, as a senior security consultant through Toptal, I assess cloud and hybrid environments against NIST CSF and CIS Controls and design federated authentication for logistics and freight API platforms.
Governance, risk and compliance
POA&M ownership, security plan documentation, control gap analysis, audit readiness and evidence management against NIST 800-171, CMMC, NIST CSF and CIS Controls.
Security program delivery
PMP and SAFe program management, aligning engineering, internal security and assessor teams through full assessment cycles.
Connected and autonomous vehicles
Telematics, CAN bus, ECU and OTA update security, fleet platform migration, and hardware-in-the-loop testing.
Three programs where the work had to stand up to scrutiny.
Rebuilt the governance so the program could survive external assessment.
Contract role in Caterpillar's defense business. Rebuilt the program's governance and documentation architecture, owned the POA&M from control gap to closure, and sustained evidence packages through external assessment. Drove NIST 800-171 and CMMC readiness and government cloud authorization prep, and directed AWS cloud security testing and secure baseline review, issuing architecture standards the program's network and infrastructure architects adopted.
Mapped control libraries to each client's real obligations.
Delivered security governance for Visa Europe, Samsara AI and Lineage Logistics, mapping policies, standards and control libraries to each client's regulatory obligations, including GDPR. Delivered compliance readiness for the City of Seattle against NIST 800-171 and government cloud authorization criteria: control gap analysis, evidence planning and remediation roadmaps ahead of formal assessment.
Moved a luxury fleet from CalAmp to Geotab and secured the platform underneath.
Led the CalAmp to Geotab platform migration across a luxury vehicle fleet and wrote the Go platform integration behind it. Raised secure device provisioning throughput 40% by implementing API security and access control across shared services on a multi-tenant AWS and Kubernetes platform.
Six layers of a connected vehicle. Every one worked in.
Most security leads arrive at vehicles from the policy side. My work runs through the whole stack, from the site network to identity and API access. Select a layer to see where it happened.
Identity and API access
Designed federated authentication for logistics and freight API platforms using OpenID Connect and JWT, and assessed client cloud and hybrid environments against NIST CSF and CIS Controls.
Fifteen years of practice, a decade in vehicle systems.
ATLANTA, GA
REMOTE
ATLANTA, GA
GRIFFIN, GA
BIRMINGHAM, AL
REMOTE
BELMONT, CA
BOISE, ID
ATLANTA, GA
ATLANTA, GA
MORROW, GA
GEORGIA