About
Cybersecurity architect turned AI-native security builder.
Over 12+ years I've designed, deployed, and operated security at the scale that Fortune 100 enterprises and global financial institutions demand — Zero Trust, SASE, NGFW architecture, NAC, microsegmentation, and cloud security across AWS and Azure.
Today I connect security architecture, operational telemetry, AI automation, and governance into practical systems. I build platforms that correlate firewall policy, Cisco ISE / NAC authorization logs, routing data, and infrastructure telemetry — reducing investigation time, improving audit readiness, and strengthening Zero Trust enforcement.
My work sits at the intersection of enterprise security engineering and applied AI: RAG pipelines, LLM reasoning, and agentic workflows that turn fragmented security data into evidence-backed answers.
- Zero Trust by default: Least privilege, continuous verification, and identity-aware segmentation as first principles — not afterthoughts.
- Automation over toil: Deterministic validation and AI-assisted reasoning that compress 45-minute investigations into minutes.
- Governed AI: AI introduced into SecOps with traceability, compliance alignment, and secure data pipelines.
- Evidence-backed answers: Every recommendation is grounded in policy, logs, and telemetry — audit-ready by design.
Expertise
- AI-Driven Security Operations: LLM + RAG pipelines that correlate telemetry, automate investigation, and surface engineering insight.
- Zero Trust Architecture: Least-privilege, identity-centric access and continuous verification across hybrid estates.
- SASE / ZTNA: Converged network security: SWG, CASB, FWaaS, and ZTNA for secure remote access.
- Firewall Policy Optimization: Detect shadowed, redundant, unused, and overly permissive rules; enforce least privilege.
- NAC / Cisco ISE: Identity-aware ACLs, posture, and automated remediation across the access layer.
- Cloud Security: AWS & Azure: Cloud security controls, posture, and architecture for complex multi-cloud deployments.
- Palo Alto / Cisco / Fortinet: NGFW architecture, Panorama, Firepower/FTD/FMC, and multi-vendor security engineering.
- Microsegmentation: Boundary design and deterministic validation to stop lateral movement.
- RAG & LLM-Powered Automation: Retrieval-augmented reasoning over policy, logs, and routing for security workflows.
- Agentic Security Workflows: AI agents that triage, classify, and remediate using LangChain & LangGraph.
- Security Governance & Compliance: Policy mapping to standards, audit readiness, and regulatory-aligned SecOps.
- Financial-Sector Cybersecurity: Security engineered for hedge funds and global banks under SEC / OCIE constraints.
Projects
FirewallIQ
AI Firewall Governance & Remediation Platform
A decision system for firewall policy operations: set-math analysis, reachability graphs, and zero-false-deny proofs under strict change governance.
Stack: Python, CIDR / Set Mathematics, Reachability Graphs, RAG, Simulation Engine, SHA-256 Evidence
NAC Coverage Assurance & Endpoint Visibility Platform
Enterprise NAC Coverage Assessment & Endpoint Visibility
Enterprise NAC coverage assessment for Cisco ISE and switch environments: eligible-port analysis, drift detection, and endpoint visibility.
Stack: Python, Cisco ISE, Cisco Switches, 802.1X / MAB, MAC/OUI Profiling, Scheduled Scans, Email Reporting
AI-Driven Security Investigation Platform
LLM platform correlating firewall policy, Cisco ISE logs, and routing data to cut diagnostic latency by 75%.
Stack: Python, LLMs, RAG, LangChain, Cisco ISE, BGP/OSPF
Zero Trust / SASE Architecture for Financial Institutions
Zero Trust and Prisma Access / SASE for large financial environments: least privilege, reduced attack surface, secure remote access.
Stack: Prisma Access, ZTNA, SASE, AI Analytics
Enterprise Firewall Migration Leadership
Led 35+ large-scale firewall migrations across Cisco ASA, Palo Alto, Fortinet, Check Point, Juniper, and Firepower.
Stack: Cisco ASA, Palo Alto, Fortinet, Firepower, Ansible
AI-Native Security Copilot — Nexa Copilot Concept
Security copilot concept: natural-language queries across firewalls, NAC, cloud, and policy with evidence-backed answers.
Stack: RAG, LangGraph, LLMs, Python, Vector Search
Experience
Sr Security Consultant — Point72 Asset Management
Oct 2025 — Present · New York, USA
AI-driven security automation, firewall governance, NAC governance, Zero Trust validation, financial-sector workflows.
- Built AI-driven security automation using Python, REST APIs, LLMs, RAG, LangChain, and LangGraph to correlate operational data and generate actionable engineering insight.
- Developed an AI-enabled Palo Alto firewall governance & remediation platform (FirewallIQ) — cut policy review time 60% and improved audit readiness and traceability.
- Built an enterprise NAC coverage assessment and endpoint visibility platform for Cisco ISE and switch environments — automated eligible-port analysis, drift detection, and remediation gap reporting across thousands of switchports.
- Operationalized Zero Trust controls via deterministic validation of identity-aware ACLs and microsegmentation — reduced diagnostic latency 75% (45 min → <5 min).
- Designed a RAG-based Security Intelligence Platform for national financial networks via a secure hub-and-spoke model.
Senior SASE / Zero Trust Consultant — J.P. Morgan & Co.
Jun 2024 — Oct 2025 · Jersey City, USA
Prisma Access, ZTNA, SASE, AI analytics, remote access security for a global financial institution.
- Designed and deployed Palo Alto Prisma ZTNA to enforce least-privilege access and replace traditional VPN risk.
- Engineered AI-driven analytics within the SASE architecture — 30% reduction in MTTD and 50% increase in proactive risk mitigation.
- Built Python / REST API solutions for security automation and real-time log analysis.
- Led design and execution of a Palo Alto SASE proof-of-concept under strict regulatory and compliance standards.
Senior Security Consulting Engineer — Cisco Systems
Jan 2023 — Apr 2024 · New York, USA
Fortune 100 security architecture, Cisco SASE, Firepower/FTD, ISE, Zero Trust, ransomware remediation.
- Led customer-facing discovery, architecture, PoC execution, and production deployment for Fortune 100 environments.
- Implemented ZTNA and microsegmentation with Cisco security solutions to prevent unauthorized lateral movement.
- Configured Cisco SASE — CASB, ZTNA, and FWaaS — for comprehensive, seamless protection.
- Directed technical peer reviews, mentored new hires, and delivered HLD/LLD and training curricula.
Senior Network Security Engineer — Altice USA
Mar 2022 — Jan 2023 · New York, USA
Firewall policy, Panorama, Cisco FMC, lab validation, cloud security controls.
- Leveraged Panorama and Cisco FMC for unified policy enforcement and comprehensive reporting.
- Applied deep TCP/IP, BGP, OSPF, EIGRP, NAT, and VPN expertise to architect and troubleshoot secure networks.
- Defined cloud security controls and led on-prem-to-Azure security assessments at enterprise scale.
- Maintained validation labs with scale, performance, and topology testing using IXIA and SPIRENT.
Security Consulting Engineer — Cisco Systems
Jul 2018 — Jan 2022 · Chicago, USA
Firewall migrations, Python/Ansible automation, Zero Trust remote access, ransomware remediation.
- Built Python and Ansible automation for rule deployment, migration gap analysis, and compliance checks.
- Led multi-vendor migrations (Check Point, Juniper, Palo Alto, SonicWall) to Cisco Firepower Threat Defense.
- Architected emergency Zero Trust remote access for healthcare during COVID-19 — scaled AnyConnect VPN with posture validation (HIPAA).
- Served as lead technical consultant on Maze ransomware remediation for a Fortune 500 provider.
Network Security Engineer — Northern Trust Corporation
May 2017 — Apr 2018 · Chicago, USA
FirePOWER, Cisco ISE, Gigamon, secure network architecture for banking.
- Configured FirePOWER 9300 clustered mode and integrated Cisco ISE for automated remediation.
- Completed Cisco ACS to Cisco ISE 2.2 migrations using automated and manual processes.
- Deployed Gigamon network security tap and analysis tooling.
- Validated architecture and design to produce detailed engineering specifications.
Network Security Engineer — Capgemini
Sep 2014 — Dec 2015 · Bengaluru, India
Palo Alto, Cisco ASA, Sourcefire, VPNs, incident/change management, data center security.
- Configured Palo Alto / Cisco ASA firewalls, zone-based firewalling, and security rules.
- Managed Sourcefire NGIPS/IDS and analyzed results for threat response.
- Built site-to-site IPsec VPN tunnels between client and partner sites.
- Handled incident and change management and data center connectivity troubleshooting.
Books
The Gen AI Security Playbook
Practical Defenses for GenAI Applications
A practitioner's playbook for defending GenAI — covering model risk, secure data pipelines, prompt and context threats, and governance for AI in the enterprise.
Architecting Zero Trust with AI
Modern Zero Trust architecture, AI-augmented
How to design and implement modern Zero Trust architectures augmented with AI — from identity-centric access and microsegmentation to AI-driven detection and response.
AI Awareness for High School Students (upcoming)
Building AI literacy & safety for the next generation
An upcoming book that makes AI literacy, safety, and responsible use accessible to high-school students — covering privacy, security fundamentals, and critical thinking for the AI era.
Research Interests
- AI Anomaly Detection for Industrial IoT: Resilient, lightweight ML models for real-time anomaly detection on resource-constrained critical-infrastructure hardware.
- Generative AI × Zero Trust Integration: Embedding GenAI into Zero Trust architectures for endpoint security — supporting SMBs and supply-chain security.
- Adversarial Training: Hardening AI models against data manipulation and sensor-spoofing attacks through adversarial techniques.
- Secure AI Data Pipelines: Designing pipelines that protect model integrity and provenance end-to-end across the AI lifecycle.
- AI Security for SMBs & Supply Chain: Accessible, deployable AI security patterns for smaller organizations and complex supply chains.
- Lightweight Real-Time Threat Models: Efficient models that enable real-time threat detection and automated response at the edge.
Skills & Tools
AI & Automation
Python, REST APIs, LLMs, RAG, LangChain, LangGraph, AI Agents, Prompt Engineering, Context Engineering, CI/CD
Security Architecture
Zero Trust, SASE, ZTNA, Microsegmentation, Firewall Governance, NAC, IAM, DLP, Incident Response
Vendors & Platforms
Palo Alto, Prisma Access, Cisco ISE, Cisco Firepower/FTD, Cisco SASE, Fortinet, AWS, Azure, Splunk, CrowdStrike, SentinelOne, Tenable
Network Security
TCP/IP, VPN, BGP, OSPF, NAT, IDS/IPS, Proxy, Web Security, Cloud Security Controls
Certifications & Education
- Cisco Security Core
- IBM Gen AI Security Professional
- Azure AZ-500 Security
- CCNA & CCNP (Security / R&S)
- PCNSE — Palo Alto
- AWS Solutions Architect
M.S. in Cybersecurity — DePaul University, Chicago (2018)
Frequently Asked Questions
Who is Digvijay Parmar?
Digvijay Parmar is an AI Security & Zero Trust Architect with 12+ years across Fortune 100 and global financial institutions, building AI-native security automation with RAG, LLMs, and AI agents.
What is FirewallIQ?
FirewallIQ is his flagship firewall policy decision system. It uses IP/CIDR/port set-mathematics and reachability graphs to detect shadowed, duplicate, and redundant rules, and generates zero-false-deny least-privilege proofs under a strict change-governance workflow.
What is the NAC Coverage Assurance Platform?
An enterprise NAC assurance and endpoint visibility platform for Cisco ISE and switch environments. It measures organization-wide 802.1X/MAB coverage, identifies ports missing NAC controls with intelligent eligibility logic, detects configuration drift between scans, and provides endpoint visibility via MAC/vendor profiling.
How can I contact or hire Digvijay?
Use the contact form on this site, email [email protected], or connect on LinkedIn at linkedin.com/in/digvijay-parmar47.
Contact
Email: [email protected]
Phone: +1 312-678-4223
LinkedIn: https://www.linkedin.com/in/digvijay-parmar47/
GitHub: https://github.com/digvijay378