Michael Golden Jr.
LOADING PORTFOLIO
Open to cybersecurity PM and GRC roles · Metro Atlanta
CYBERSECURITY PROGRAM MANAGER · GRC · TPM
SMYRNA, GA · METRO ATLANTA

Securitythatholdsup
underoutsidereview.

Cybersecurity program manager with a decade inside connected and autonomous vehicle systems. Rebuilt governance on a U.S. Navy marine engine cybersecurity program at Caterpillar, cutting documentation cycle time about 40% and lifting risk detection about 30%. Owned the POA&M from control gap to closure. CISSP. PMP. SAFe 6.

Portrait of Michael Golden Jr. in a dark suit and tie
MG · METRO ATLANTA
CISSP · 2026
ABOUT0%
DOCUMENTATION CYCLE
TIME CUT, NAVY PROGRAM
ABOUT0%
RISK DETECTION LIFT
SAME PROGRAM
0%
TELEMATICS TESTING
CYCLES CUT, CATERPILLAR
0%
SECURE PROVISIONING
THROUGHPUT, CLUTCH
THE THESIS

A control is a claim.
Evidence is the proof.

Security programs rarely fail on the controls themselves. They fail at the handoff between the people who build a system and the people who have to certify it. That handoff is my job: choosing the controls that actually apply, planning the evidence before anyone asks for it, tracking every gap to closure, and keeping engineering, internal security and assessors aligned until the review is done.

THE EVIDENCE STANDARD

From control gap to closure.

The lifecycle I ran on the U.S. Navy marine engine cybersecurity program at Caterpillar, where I owned the POA&M end to end. Step through it to follow one item from the day a gap is found to the day an assessor accepts it.

POA&M ITEM  TRACKED FROM GAP TO CLOSURE
OPEN
STAGE 1 OF 5

Control selection

Which controls does this system actually have to meet?

Scoping starts with the obligation. On the Navy program I drove NIST 800-171 and CMMC readiness and government cloud authorization prep, beginning with control selection so every later step measured against the right baseline.

WHAT THIS STAGE PRODUCES
A selected control baseline tied to NIST 800-171, CMMC and cloud authorization criteria
WHO I ALIGN
Engineering and internal security

Program result: documentation cycle time down about 40%, risk detection up about 30%.

Stage content describes my role and the artifacts I owned. It is not a record of any specific finding on the program.

A vehicle technologist, now securing the systems I used to build.

My route into security ran the opposite way from most. Before governance, there was engineering: installing telematics hardware, testing ECUs on the bench, migrating fleet platforms and assessing over-the-air update pipelines for signing and tamper exposure. That background is why my control reviews reach the ECU, not just the policy binder.

At Caterpillar, on a U.S. Navy marine engine cybersecurity program in the company's defense business, I rebuilt the governance and documentation architecture, authored the security plan documentation, and served as primary liaison to federal oversight stakeholders and external certification bodies including ABS.

Through my independent practice I have delivered security governance for Visa Europe, Samsara AI and Lineage Logistics, mapping policies, standards and control libraries to each client's obligations, including GDPR, and compliance readiness for the City of Seattle against NIST 800-171.

Today, as a senior security consultant through Toptal, I assess cloud and hybrid environments against NIST CSF and CIS Controls and design federated authentication for logistics and freight API platforms.

Michael Golden Jr.
Michael Golden Jr.
CISSP · PMP · SMYRNA, GA
PILLAR ONE

Governance, risk and compliance

POA&M ownership, security plan documentation, control gap analysis, audit readiness and evidence management against NIST 800-171, CMMC, NIST CSF and CIS Controls.

PILLAR TWO

Security program delivery

PMP and SAFe program management, aligning engineering, internal security and assessor teams through full assessment cycles.

PILLAR THREE

Connected and autonomous vehicles

Telematics, CAN bus, ECU and OTA update security, fleet platform migration, and hardware-in-the-loop testing.

Three programs where the work had to stand up to scrutiny.

01
CATERPILLAR INC. · 2023 TO 2024
Senior Validation Engineer and Program Manager
ABOUT40%
DOCUMENTATION CYCLE TIME CUT
U.S. NAVY MARINE ENGINE CYBERSECURITY PROGRAM

Rebuilt the governance so the program could survive external assessment.

Contract role in Caterpillar's defense business. Rebuilt the program's governance and documentation architecture, owned the POA&M from control gap to closure, and sustained evidence packages through external assessment. Drove NIST 800-171 and CMMC readiness and government cloud authorization prep, and directed AWS cloud security testing and secure baseline review, issuing architecture standards the program's network and infrastructure architects adopted.

ABOUT 30%
RISK DETECTION LIFT
POA&M
OWNED GAP TO CLOSURE
ABS
CERTIFICATION BODY LIAISON
02
GOLDEN GROUP CONSULTING · 2011 TO PRESENT
Principal, independent cybersecurity advisory practice
NIST 800-171
CITY OF SEATTLE READINESS
ENTERPRISE AND PUBLIC SECTOR GOVERNANCE

Mapped control libraries to each client's real obligations.

Delivered security governance for Visa Europe, Samsara AI and Lineage Logistics, mapping policies, standards and control libraries to each client's regulatory obligations, including GDPR. Delivered compliance readiness for the City of Seattle against NIST 800-171 and government cloud authorization criteria: control gap analysis, evidence planning and remediation roadmaps ahead of formal assessment.

GDPR
REGULATORY MAPPING
GAP
ANALYSIS AND ROADMAPS
GOV CLOUD
AUTHORIZATION CRITERIA
03
CLUTCH TECHNOLOGIES · 2018 TO 2019
Telematics and Cloud Engineer
40%
SECURE PROVISIONING THROUGHPUT
CONNECTED FLEET PLATFORM

Moved a luxury fleet from CalAmp to Geotab and secured the platform underneath.

Led the CalAmp to Geotab platform migration across a luxury vehicle fleet and wrote the Go platform integration behind it. Raised secure device provisioning throughput 40% by implementing API security and access control across shared services on a multi-tenant AWS and Kubernetes platform.

GO
PLATFORM INTEGRATION
AWS, K8S
MULTI-TENANT
API
SECURITY AND ACCESS CONTROL

Six layers of a connected vehicle. Every one worked in.

Most security leads arrive at vehicles from the policy side. My work runs through the whole stack, from the site network to identity and API access. Select a layer to see where it happened.

LAYER 6 OF 6

Identity and API access

TOPTAL · 2025 TO PRESENT

Designed federated authentication for logistics and freight API platforms using OpenID Connect and JWT, and assessed client cloud and hybrid environments against NIST CSF and CIS Controls.

The governance rail: NIST 800-171, CMMC and NIST CSF tie the layers together. That is the program work, and it only holds when the engineering underneath is understood.

Fifteen years of practice, a decade in vehicle systems.

2011 TO PRESENT
ATLANTA, GA
Principal
GOLDEN GROUP CONSULTING · INDEPENDENT CYBERSECURITY ADVISORY
Delivered security governance for Visa Europe, Samsara AI and Lineage Logistics, mapping policies, standards and control libraries to each client's regulatory obligations, including GDPR. Delivered compliance readiness for the City of Seattle against NIST 800-171 and government cloud authorization criteria: control gap analysis, evidence planning and remediation roadmaps ahead of formal assessment.
GDPR MAPPING
NIST 800-171
JAN 2025 TO PRESENT
REMOTE
Senior Security Consultant
TOPTAL
Assessed client cloud and hybrid environments against NIST CSF and CIS Controls, turning findings into remediation roadmaps with named owners and closure targets. Designed federated authentication for logistics and freight API platforms using OpenID Connect and JWT.
NIST CSF
OIDC, JWT
FEB 2025 TO MAR 2025
ATLANTA, GA
IT Consultant, Autonomous Vehicle Programs
MOOVE MOBILITY
Designed and built the MDF and IDF network and segmentation architecture for the Atlanta autonomous vehicle program, with physical and environmental controls protecting AV control and telemetry systems.
AV NETWORK
SEGMENTATION
JUL 2023 TO MAY 2024
GRIFFIN, GA
Senior Validation Engineer and Program Manager
CATERPILLAR INC. · CONTRACT · DEFENSE BUSINESS, U.S. NAVY MARINE ENGINE CYBERSECURITY PROGRAM
Cut documentation cycle time about 40% and raised risk detection about 30% by rebuilding the program's governance and documentation architecture. Owned the POA&M from control gap to closure, authoring security plan documentation and sustaining evidence packages through external assessment. Served as primary liaison to federal oversight stakeholders and external certification bodies including ABS. Drove NIST 800-171 and CMMC readiness and government cloud authorization prep, and directed AWS cloud security testing and secure baseline review.
ABOUT 40% CYCLE TIME
ABOUT 30% DETECTION
POA&M OWNER
DEC 2022 TO MAR 2023
BIRMINGHAM, AL
Telematics Test Engineer and Project Engineer
TRIZ ENGINEERING SERVICE AMERICA LLC · GVW GROUP
Assessed over-the-air update pipelines for signing, delivery path integrity and tamper exposure across onboard ECUs and backend infrastructure. Consolidated vehicle data gathering into one platform, unifying telemetry collection across EV and fleet programs.
OTA SECURITY
FEB 2021 TO SEP 2022
REMOTE
Telematics Test and Quality Engineer
CATERPILLAR INC. · CONTRACT
Cut testing cycles 50% and improved analytics accuracy 35% by validating telematics data paths from CAN bus and ECU sources through backend platforms, in transit and at rest. Core team member on a nationwide telematics architecture change covering all Caterpillar assets. Ran hardware-in-the-loop bench testing on dSPACE MicroAutoBox with Vector CAN analysis, and built SQL data pipelines and Power BI dashboards for executive risk reporting.
50% TESTING CYCLES
35% ACCURACY
JUN 2022 TO SEP 2022
BELMONT, CA
Telematics Test Engineer
VOLKSWAGEN GROUP · CONTRACT
Improved defect resolution 22% by validating secure communication channels between connected vehicle systems and backend cloud services.
22% DEFECT RESOLUTION
JAN 2020 TO DEC 2020
BOISE, ID
Telematics Subject Matter Expert
MARSHALLGIS · CONTRACT
Led cloud and GPS platform deployments across fleets of 1,200 and more than 4,000 connected assets, owning secure device provisioning, asset inventory and lifecycle handling.
4,000 ASSET FLEET
OCT 2019 TO DEC 2019
ATLANTA, GA
Autonomous Vehicle Support Analyst
LOCAL MOTORS · CONTRACT
Supported AV fleet operations across telemetry collection, onboard data handling and operational monitoring.
AV OPERATIONS
OCT 2018 TO AUG 2019
ATLANTA, GA
Telematics and Cloud Engineer
CLUTCH TECHNOLOGIES
Led the CalAmp to Geotab platform migration across a luxury vehicle fleet, writing the Go platform integration behind it. Raised secure device provisioning throughput 40% by implementing API security and access control across shared services on a multi-tenant AWS and Kubernetes platform.
40% THROUGHPUT
GO INTEGRATION
OCT 2017 TO OCT 2018
MORROW, GA
Production Control Manager
DIXIEN LLC OF ATLANTA · CONTRACT MANUFACTURER SUPPLYING NISSAN AND BMW
Ran daily operations of a $7M annual forecast production line spanning six departments, 80 associates and two locations. Aligned 20 international suppliers to JIT timelines against supplier scorecards for custom parts supplied to BMW Germany and Nissan.
80 ASSOCIATES
20 SUPPLIERS
2012 TO 2017
GEORGIA
Earlier technical experience
UEI COLLEGE · CUBIC TRANSPORTATION SYSTEMS · DESCARTES SYSTEMS GROUP · NCR CORPORATION
Field and bench technical roles across telematics installation, transit fare collection, warehouse management systems and point-of-sale hardware, plus a 2017 instructor role at UEI College.

Certifications, education and the frameworks I work against.

GRADUATE
M.S., Information Technology
Liberty University, Network Design and Security specialization
2026
UNDERGRADUATE
B.A., General Studies
Southern New Hampshire University
2023
CERTIFICATIONS
CISSP · ISC2 2026
PMP
SAFE 6 AGILIST
SAFE 5 AGILIST
COMPTIA SECURITY+
COMPTIA PROJECT+
FRAMEWORKS AND REGULATIONS
NIST CSF
NIST SP 800-53
NIST SP 800-171
CMMC
FEDRAMP READINESS
STATERAMP READINESS
ISO 27001
CIS CONTROLS
GDPR
ISA/IEC 62443
PROFESSIONAL COMMUNITY
ISC2 ATLANTA
ISACA BIRMINGHAM
PMI ATLANTA · EVENT COORDINATOR 2017 TO 2019
PMI CENTRAL ALABAMA

Have a program that has to pass review?

Open to cybersecurity program and project manager, IT governance, risk and compliance manager, and technical program manager roles in the Atlanta area.