Bright T Pfupa

Cybersecurity Architect & Cloud Security Engineer | Azure Infrastructure Engineer | SC-100 | SC-401 | AZ-500 | AZ-104 | SC-300 | SC-900 | AZ-900 | ISO/IEC 42001:2023 LA | ISO/IEC 27001:2022 LA

Zimbabwe

About

Cybersecurity isn’t just about locks; it’s about enabling growth. I am a Microsoft Certified Cybersecurity Architect Expert dedicated to securing enterprise infrastructure by aligning technical defense with corporate strategy. My approach is rooted in the Microsoft Cloud Security Benchmark (MCSB) and Zero Trust architecture. ​From my roots in network troubleshooting to my tenure as a Senior Technical Support Engineer, I have developed a 360-degree view of the threat landscape. Today, I help organizations navigate the complexities of: ​✅ AI Governance: Lead Auditor for ISO/IEC 42001 (AI Management Systems). ✅ Enterprise Defense: End-to-end management of the Microsoft Defender & Sentinel ecosystems. ✅ Hybrid Identity: Architecting secure Entra ID and Conditional Access environments. ✅ Risk Compliance: Driving ISO 27001 readiness and GRC excellence. ​I specialize in "hardening by design", ensuring that every digital asset is protected while supporting seamless organizational scale. ​Let’s connect if you are looking for a security partner who understands both the CLI and the ROI. 🌍 Open to Global Opportunities in: Cybersecurity Architect| Cloud Security Engineer | Azure Infrastructure Engineer

Experience

  • Liquid Intelligent Technologies (Full-time · 5 yrs 9 mos)
    • Datacenter Technician
      May 2026 - Present · 2 mos

    • Senior Technical Support Engineer
      Jul 2022 - May 2026 · 3 yrs 11 mos

      - Led resolution of complex technical issues escalated by Account Managers and Heads of Department, ensuring swift action for VIP enterprise clients, maintaining 100% adherence to strict SLA commitments. - Managed high‑priority incidents, coordinated with NOC and engineering teams, and delivered timely solutions to minimize business impact. - Oversaw escalations from Tier 1 and Tier 2 teams, provided advanced troubleshooting, and ensured adherence to SLA commitments. - Directed service restoration efforts during critical outages, communicated status updates to stakeholders, and ensured transparent reporting. - Hardened tenant security by administering advanced DNS records (SPF, DKIM, DMARC) to mitigate spoofing and ensure reliable, secure mail flow. - Provided advanced support for customers with website hosting on cPanel, diagnosed outages, performed root cause analyses, and recommended targeted fixes to restore performance and enhance reliability. - Executed Microsoft 365 migrations, migrated mailboxes, configured hybrid environments, and enabled seamless adoption of Exchange Online, Teams, and OneDrive. - Trained and Mentored junior engineers by sharing best practices, reviewing escalated cases, and strengthening team capability in handling enterprise workloads, reducing repeat escalations by 40%. - Collaborated with cross‑functional teams to implement long‑term fixes, reduce repeat escalations, and enhance operational resilience. -Provided Tier 1 & Tier 2 support for VoIP systems, diagnosing and resolving call quality, latency, and connectivity issues.

    • Technical Support Engineer
      Oct 2020 - Jun 2022 · 1 yr 9 mos

      - Network Troubleshooting and Resolution: Diagnosed and resolved connectivity issues across broadband, fiber, and wireless networks, ensuring minimal downtime for customers. - Customer Support Excellence: Delivered Tier 1 technical support via phone, email, and remote tools, achieving first-call resolution. - Service Provisioning and Configuration: Assisted with router, modem, and firewall setup, including PPPoE, DHCP, DNS, and VLAN configurations for residential and Enterprise clients. - Escalation and Collaboration: Escalated complex cases to NOC, Field technicians and engineering teams, documenting root causes and contributing to long-term fixes. - Knowledge Base and Documentation: Created step-by-step guides and FAQs to improve customer self-service and reduce repetitive support queries. - Security Awareness: Supported customers with safe internet practices, basic firewall rules, and malware prevention guidance.

  • Information System Administrator at Interoll Agro
    Jan 2020 - Jul 2020 · 7 mos

    - Administered on‑premises Active Directory Domain Services (AD DS), managed user accounts, groups, and organizational units, and enforced Group Policy Objects to strengthen security and compliance. - Maintained Windows Server infrastructure, applied patches and updates, and ensured system availability and performance across enterprise environments. - Configured and monitored DNS, DHCP, and file/print services, optimized resource allocation, and resolved service interruptions. - Implemented backup and disaster recovery strategies, tested failover procedures, and safeguarded business continuity. - Diagnosed server and network issues, performed root cause analyses, and applied corrective actions to minimize downtime. - Provisioned new servers and applications, migrated workloads, and supported infrastructure scalability for growing business needs. - Troubleshot LAN/WAN connectivity problems, analyzed packet flows, and restored network performance for enterprise users. - Configured and maintained routers and switches, applied VLANs, ACLs, and QoS policies, and ensured secure, efficient traffic management - Collaborated with department heads to align IT services with organizational goals and delivered tailored solutions for enterprise operations. - Monitored system logs and security events, identified vulnerabilities, and implemented remediation measures to protect against threats. - Documented infrastructure changes, developed SOPs, and trained staff to enhance IT awareness and operational efficiency.

  • Information Technology Intern at Chitungwiza Municipality
    Jan 2018 - Dec 2018 · 1 yr

    - Administered Active Directory Domain Services (AD DS), created and managed user accounts, groups, and organizational units under supervision. - Supported Sophos firewall administration, configured web and time‑based access policies, and monitored compliance with organizational security standards. - Diagnosed network connectivity issues, troubleshot LAN/WAN problems, and escalated network outages to ISP. - Configured and tested routers and switches, applied VLANs and access rules, and ensured secure traffic segmentation. - Monitored system logs and firewall alerts, identified potential threats, and reported findings to the IT security team. - Assisted with Windows Server patching and updates, verified system stability, and documented maintenance activities. - Supported end‑user requests, resolved hardware/software issues, and guided staff on IT best practices. - Participated in backup and recovery testing, validated data integrity, and ensured readiness for disaster recovery scenarios. - Documented troubleshooting steps and contributed to internal knowledge base articles to improve team efficiency.