Open to collaboration, consulting, and technology leadership opportunities.

OngeziweMgudlwa

Technology Leader  ·  Cybersecurity  ·  Infrastructure  ·  Digital Transformation

Technical enough to build, security-minded enough to defend, and ambitious enough to turn practical solutions into products that improve how people live and work.

10+
Years in Tech
4
Active Projects
ZA
South Africa
Ongeziwe Mgudlwa — Technology Leader
🔨

Build

Creating practical technology solutions and products that solve real problems. From home lab infrastructure to cybersecurity platforms, I ship things that work.

🛡️

Defend

Applying security-first thinking to protect people, systems, and businesses. Security isn't a feature—it's the foundation everything else is built on.

Transform

Leveraging technology to change how people live and work. Digital transformation isn't about tools—it's about outcomes that matter to real people.

About

Builder. Defender.
Innovator.

I'm a technology leader with over a decade of experience directing technology programmes, shaping security strategy, and leading digital transformation across enterprise environments in South Africa.

My work sits at the intersection of leadership and execution. I have chaired technology steering committees, managed vendor relationships and commercial negotiations, built office IT environments from the ground up, and developed people-centred IT cultures that treat members—not users—as the measure of success.

On the security side, I have led risk assessments, implemented SOC 2 compliance initiatives, deployed security awareness programmes, and built phishing simulation campaigns that measurably change behaviour. I understand cybersecurity not as a checklist but as a leadership responsibility.

Today I'm channelling that depth of experience into building products—turning real-world problems I've solved inside organisations into scalable tools that help others defend, transform, and grow.

My north star: practical solutions that actually get used. Not theoretical frameworks. Not checkbox compliance. Real impact for real people.

Core Competencies
Technology Leadership Cybersecurity Strategy Infrastructure Design Cloud Security Active Directory Endpoint Protection Security Awareness Incident Response Network Architecture Digital Transformation Automation Python Linux SIEM Docker Home Lab
Leadership Experience

Capabilities Built in the Field

Experience developed through years of leading technology programmes, managing people, and solving real organisational problems.

🏗️

Technology Leadership

  • IT Project Management
  • Technology Infrastructure Oversight
  • Service Improvement Initiatives
  • IT Steering Committee Leadership
  • Digital Transformation
🛡️

Security & Risk

  • Cybersecurity Risk Assessments
  • SOC 2 Compliance Initiatives
  • Security Awareness Programs
  • Phishing Simulations
  • Email Security Implementations
🤝

Vendor & Commercial Management

  • Vendor Evaluation & Procurement
  • Contract & Commercial Discussions
  • Vendor Negotiation
  • Cost Optimisation
  • Technology Investment Decisions
📚

Learning & Enablement

  • Lunch & Learn Programs
  • Knowledge Base Development
  • Technical Documentation
  • Security Awareness Content
  • Employee Development
⚙️

Automation & Innovation

  • Python Automation
  • Jamf Administration & Automation
  • Process Improvement
  • Workflow Optimisation
  • Operational Efficiency
Leadership Highlights

What I've Delivered

A selection of real outcomes from leading technology programmes and teams.

Negotiated vendor discounts and reduced technology costs without sacrificing capability or service quality.

Built and launched complete office IT environments from the ground up—infrastructure, security, and support workflows.

Chaired technology steering committee discussions, aligning technology decisions with organisational strategy.

Helped transform IT culture by shifting the focus from users to members—a change that improved satisfaction and trust.

Built knowledge management systems that reduced support dependency and empowered teams to self-serve effectively.

Improved IT asset lifecycle management and operational efficiency across the technology environment.

Encouraged continuous learning and professional development as a core part of building strong technology teams.

Beyond Technology

The Full Capability Picture

Technology leadership requires more than technical skill. These are the disciplines that make the difference between a good technologist and an effective leader.

Stakeholder Management Executive Communication Vendor Negotiation Contract Management Budget Optimisation Technology Procurement Change Management Security Awareness Learning Design Team Development Process Improvement Cross-Functional Collaboration
Featured Projects

What I'm Building

Practical tools at the intersection of security awareness, infrastructure, and automation.

📱
Live
Smish-Aware
Smishing Awareness & Detection Platform
A platform designed to combat SMS phishing—one of the fastest-growing social engineering vectors. Smish-Aware educates users through interactive training modules, real-world simulation, and threat intelligence dashboards.
Architecture
SMS Gateway → Detection Engine → Awareness Portal
User Reporting → Analytics Dashboard → Admin Console
Python SMS APIs Threat Intel Dashboard
Security Awareness Smishing
🚀 Visit Live Platform →
Live production platform
🔒
Running
Pi-Hole DNS Filtering & Infrastructure Monitoring Lab
DNS Filtering, Monitoring & Security Hardening
Built and deployed a Raspberry Pi-based DNS filtering and infrastructure monitoring solution to improve privacy, reduce advertising traffic, and provide visibility into network activity across multiple devices. The platform combines Pi-hole, Unbound, Grafana, and Prometheus to deliver centralized DNS filtering, recursive DNS resolution, infrastructure monitoring, and performance analytics.
Architecture
Client → Pi-hole (DNS Sinkhole) → Unbound (Recursive)
→ Root DNS Servers · No external forwarders · Full logs
Raspberry Pi Pi-hole Unbound Linux DNS
Home Lab Privacy
GitHub link coming soon
🎮
Coming Soon
PhishBusters
Gamified Security Awareness Platform
PhishBusters is a gamified security awareness platform concept designed to transform phishing detection into a daily habit. Users earn points, unlock achievements, complete simulations, build streaks, and compete on leaderboards while improving their ability to identify phishing, smishing, and social engineering attacks.
PhishBusters Dashboard
Architecture
Challenge Engine → Points & XP → Achievement System
Security Simulations → Awareness Scoring → Leaderboards
Training Modules → Progress Tracking → Risk Reduction
Gamification Security Awareness Human Risk Smishing
Concept & Prototype Stage Cybersecurity
🛡️ Future integration with Smish-Aware simulations and awareness training
🎯
Smish Simulations
SMS Phishing Awareness & Behavioural Analytics
Designed and delivered SMS phishing (smishing) awareness simulations to measure user susceptibility, reinforce secure behaviour, and improve organisational resilience against social engineering attacks. The platform delivers realistic SMS scenarios, immediate awareness training for users who engage with simulated attacks, and campaign analytics that help identify behavioural trends and awareness gaps.
SMS Simulation Awareness Landing Page Campaign Results
Architecture
Challenge Engine → Points & XP → Achievement System Security Simulations → Awareness Scoring → Leaderboards Training Modules → Progress Tracking → Risk Reduction
🚀 Concept & Prototype Stage
Credentials

Certifications & Training

Continuous investment in staying current with the evolving technology and security landscape.

🔐
CompTIA Security+
CompTIA
Certified
☁️
AWS Certified Cloud Practitioner
Amazon Web Services
Certified
🛡️
Google Cybersecurity Professional
Google / Coursera
Certified
🎓
CISSP Candidate
ISC² — In Pursuit
In Progress
Professional Growth

The CISSP Journey

Falling short on the first attempt strengthened my commitment to mastering the discipline and returning stronger. The CISSP is one of the most demanding certifications in the field—and that first sit clarified exactly where my preparation needed to deepen. I returned to structured study with greater focus, better strategy, and a more honest understanding of what mastery at this level requires. The pursuit continues.

Retake in Progress
"Every setback in learning is a diagnostic, not a verdict. The leaders who grow fastest are those willing to sit with uncomfortable feedback and use it. Falling short on the first attempt is not failure—it is the beginning of a more informed pursuit."
📚
Perpetual Learner
Currently pursuing CISSP and deepening cloud security architecture expertise. Learning never stops.
Active
Thought Leadership

Blog & Learnings

Documenting the journey—insights from building, defending, and leading in the technology space.

Security Philosophy

The Sandpit Principle: Why Security Should Create Confidence, Not Fear

As a father of two boys, I've learned that confidence comes from creating safe environments where people can learn, explore, make mistakes, and grow. It's a lesson that has shaped how I think about security awareness, leadership, and human risk.

5 min read Read
Home Lab

Building a Privacy-First DNS Architecture with Pi-hole and Unbound

A complete walkthrough of my home lab DNS setup—eliminating third-party resolvers, gaining full network visibility, and blocking thousands of trackers at the DNS layer.

8 min read Read
Leadership

The Technology Leader's Dilemma: When to Build vs. When to Buy

After years of evaluating security tools, I've developed a decision framework for technology leaders facing the perennial build-vs-buy question. The answer is almost never obvious.

6 min read Read
Infrastructure

Active Directory Hardening: The 10 Controls That Actually Matter

Active Directory is the crown jewel of most enterprise environments—and the most attacked. Forget the 200-page hardening guide. Here are the 10 controls with the highest ROI.

10 min read Read
Product Thinking

From Security Tool to Security Product: Lessons From Building PhishBusters

There's a wide gap between a security tool that works and a security product that people actually use. Here's what I learned crossing that gap.

7 min read Read
Resilience

Failing the CISSP and What It Taught Me About Learning at the Highest Level

I sat one of the hardest security exams in the world and didn't pass. Here's what I got wrong, what it revealed, and how I'm coming back stronger for the retake.

6 min read Read
Current Focus

What I'm Doing Now

A live snapshot of where my energy goes right now.

Building Smish-Aware & PhishBusters

Designing product architecture, building MVP features, and defining the go-to-market approach for two security awareness platforms.

CISSP Preparation

Back in structured study for the CISSP retake—working through all eight domains with renewed focus and a sharper preparation strategy.

Expanding the Home Lab

Adding threat detection, SIEM capabilities, and honeypot infrastructure for hands-on security research and skill development.

Learning Product-Led Growth

Studying how security-focused SaaS products are built, scaled, and monetised—laying the foundation for future product ventures.

Let's Connect

Ready to Build
Something?

Whether you're looking for a technology leader, a security partner, or a collaborator on your next product—I'd love to hear what you're working on.

"Technical enough to build. Security-minded enough to defend. Ambitious enough to transform."

×
×