CyberNetVoyage PT Get a quote
Independent cloud infrastructure & security engineer

Senior engineering depth, without the full-time hire.

I help small MSPs and SMB IT teams in North America with backup and disaster recovery, Microsoft 365 security and infrastructure migrations, delivered remotely, on your schedule and under your brand.

Full overlap with US Eastern & CanadaBased in Brazil (UTC-4), working your business hours
Multi-tenant MSP experienceL2/L3 escalations across many client environments
Security first, documented alwaysRunbooks, rollback plans and before/after evidence
English, Portuguese, ItalianClear written communication with your team and clients
Core services

What I take off your plate

Hands-on work in the areas where small teams most often lack depth: protection, identity and the projects nobody has time to plan properly.

Backup & disaster recovery

Acronis Cyber Protect Cloud design and deployment, protection plans and restore testing. Root-cause analysis of backup failures, including VSS conflicts, plus a licensing cost review.

AcronisVSSRestore testing

Microsoft 365 & Entra ID security

Tenant hardening, MFA and Conditional Access, admin role review and Secure Score improvement, applied consistently across one tenant or many.

Entra IDConditional AccessGraph PowerShell

Endpoint & email security

Sophos Central deployment and tuning, email protection and phishing-simulation rollout, and fixing conflicts between security agents and backup tools.

Sophos CentralCrowdStrikeRapid7

Infrastructure migrations

Active Directory and domain migrations, server upgrades, DFS-R and file server moves. Every cutover comes with a runbook, validation steps and a rollback plan.

AD DSWindows ServerDNS / DHCP

Secure remote access

Zero-trust access with Tailscale or similar for small and mid-size offices: no open ports, per-user access and simple administration.

TailscaleZero trust

Automation & reporting

PowerShell and Python automation for recurring operational work: tenant reports, onboarding, compliance checks and the spreadsheets someone fills in by hand every month.

PowerShellPythonMicrosoft Graph
For MSPs · white label

An extension of your team, behind your brand

Small MSPs often lack cloud or security depth in-house. I work under your name, in your tools and your ticket queue.

01

Tier 2/3 escalations

Overflow engineering for hard tickets, cloud issues and security incidents.

02

RMM setup & automation

Syncro (or similar) policies, alerting and PowerShell scripts.

03

Baseline compliance scanning

Automated checks across client environments, with findings and a remediation plan.

04

Documentation & runbooks

SOPs, onboarding and offboarding checklists, and centralized vendor and contact databases in SharePoint.

Fixed-scope packages

Clear scope, clear deliverable

Start with a defined outcome. Each package ends with something you can hand to your client or keep for your records.

Audit

M365 Security Baseline Audit

Review of MFA, Conditional Access, admin roles, mail flow, Secure Score and device policies.

DeliverablePrioritized findings report and remediation plan
Health check

Backup Health Check

Review of protection plans, retention, immutability, failure history and a real restore test.

DeliverableHealth report with fixes ranked by risk
Project

Migration Package

Assessment, cutover plan, migration, validation and rollback plan.

DeliverableRunbook, completed cutover and handover notes
Sprint

Tenant Hardening Sprint

Apply the baseline from the audit across one or more tenants.

DeliverableChange log and before/after Secure Score
Selected work

Recent engagements

Client names are kept confidential.

Healthcare · multi-site

Cross-domain server migration

Phased cutover of file and medical imaging application servers to a new domain: NTFS/SMB permissions validation, service accounts, scheduled tasks, GPO updates and DNS cleanup, following a phased cutover playbook.

SMB · on-premises

Windows Server 2012 → 2022

End-to-end domain controller replacement: promotion, FSMO role transfer, DHCP and DNS migration, and Robocopy-based moves of multiple file shares.

Dental practices · MSP

Backup failures traced to the root

Diagnosed recurring Acronis Cyber Protect failures down to VSS conflicts and coordinated vendor escalations until backups ran clean.

MSP client base

Endpoint & email protection rollout

Sophos Central deployment across clients, including a DNS-based mail routing workaround for single-tenant Microsoft Graph API limitations.

Enterprise · multi-cloud

Hybrid Azure for many clients

Patch management and vulnerability remediation across Windows and Linux with BigFix, CrowdStrike Falcon and Rapid7, plus hybrid architectures connecting Azure to on-premises sites.

Internal operations

Manual reporting, automated

Python automation of a monthly multi-vendor sales reconciliation, replacing hours of manual data entry with a repeatable report.

How we work

From first message to handover

  1. Tell me about your environmentTenants, tools, number of users and what is going wrong or needs to change.
  2. Scope and quoteYou get a written scope, deliverables and a price before any work starts.
  3. Delivery with least-privilege accessChanges follow an agreed plan, with rollback steps and progress updates.
  4. HandoverDocumentation, evidence and recommendations your team can act on.
Engagement models

Pick what fits the work

Fixed-price packageA defined outcome, such as an audit or a migration.
Monthly retainerA set number of hours per month for escalations, automation and ongoing security work.
HourlyShort, unpredictable tasks.
Toolbox

Platforms I work in every day

Microsoft & identity

  • Microsoft 365
  • Exchange Online
  • Entra ID
  • Intune
  • Active Directory
  • Group Policy
  • Azure

Security & backup

  • Sophos Central
  • CrowdStrike Falcon
  • Rapid7
  • Acronis Cyber Protect
  • JumpCloud
  • Delinea

Operations

  • BigFix
  • WSUS
  • ServiceNow
  • Syncro
  • Datadog
  • Grafana
  • Zabbix
  • PRTG
  • Domotz

Platforms & scripting

  • Windows Server
  • RHEL / Ubuntu / SUSE
  • VMware vSphere
  • Citrix
  • GCP
  • PowerShell
  • Python
  • Bash
At a glance
Name
Leonardo Tiviroli
Focus
Cloud infrastructure, Microsoft 365 security, backup and migrations
Experience
About 5 years in IT, across MSP, enterprise and international teams
Location
Brazil · remote · UTC-4
Education
BSc studies in Cyber/Computer Forensics, The Open University
Certifications
Sophos Central Detection & Response · Acronis Cyber Protect · AWS Cloud Practitioner · Google IT Support
About

Hi, I'm Leonardo.

I'm a Windows and Linux systems engineer who has spent the last several years inside MSPs and enterprise IT teams: patching and hardening servers, running migrations, protecting endpoints and keeping Microsoft 365 tenants in order across many clients at once.

I've worked with teams in the UK, Europe, North America and Latin America, and I know what small teams need from outside help: someone who reads the ticket properly, writes down what changed and leaves the environment better documented than before.

CyberNetVoyage is how I offer that work directly, as a fixed-scope project, a retainer or an extra pair of hands behind your brand.

Get in touch

Get a quote

Tell me about your environment and what you need done. I'll reply by email with a scope, deliverables and a price.

  • Number of tenants, sites or clients
  • Users and devices
  • Tools you use today
  • What you need done, and by when
Prefer to write directly? info@cybernetvoyage.com LinkedIn profile ↗

Your details are only used to reply to this request.