AI Security & Zero Trust Architect

Building AI-Native Security Systems for the Identity-First Enterprise.

Zero Trust, SASE, firewall governance, and AI agents for Fortune 100 and global financial institutions.

New Jersey, USA · [email protected] · LinkedIn · GitHub

About

Cybersecurity architect turned AI-native security builder.

Over 12+ years I've designed, deployed, and operated security at the scale that Fortune 100 enterprises and global financial institutions demand — Zero Trust, SASE, NGFW architecture, NAC, microsegmentation, and cloud security across AWS and Azure.

Today I connect security architecture, operational telemetry, AI automation, and governance into practical systems. I build platforms that correlate firewall policy, Cisco ISE / NAC authorization logs, routing data, and infrastructure telemetry — reducing investigation time, improving audit readiness, and strengthening Zero Trust enforcement.

My work sits at the intersection of enterprise security engineering and applied AI: RAG pipelines, LLM reasoning, and agentic workflows that turn fragmented security data into evidence-backed answers.

  • Zero Trust by default: Least privilege, continuous verification, and identity-aware segmentation as first principles — not afterthoughts.
  • Automation over toil: Deterministic validation and AI-assisted reasoning that compress 45-minute investigations into minutes.
  • Governed AI: AI introduced into SecOps with traceability, compliance alignment, and secure data pipelines.
  • Evidence-backed answers: Every recommendation is grounded in policy, logs, and telemetry — audit-ready by design.

Expertise

  • AI-Driven Security Operations: LLM + RAG pipelines that correlate telemetry, automate investigation, and surface engineering insight.
  • Zero Trust Architecture: Least-privilege, identity-centric access and continuous verification across hybrid estates.
  • SASE / ZTNA: Converged network security: SWG, CASB, FWaaS, and ZTNA for secure remote access.
  • Firewall Policy Optimization: Detect shadowed, redundant, unused, and overly permissive rules; enforce least privilege.
  • NAC / Cisco ISE: Identity-aware ACLs, posture, and automated remediation across the access layer.
  • Cloud Security: AWS & Azure: Cloud security controls, posture, and architecture for complex multi-cloud deployments.
  • Palo Alto / Cisco / Fortinet: NGFW architecture, Panorama, Firepower/FTD/FMC, and multi-vendor security engineering.
  • Microsegmentation: Boundary design and deterministic validation to stop lateral movement.
  • RAG & LLM-Powered Automation: Retrieval-augmented reasoning over policy, logs, and routing for security workflows.
  • Agentic Security Workflows: AI agents that triage, classify, and remediate using LangChain & LangGraph.
  • Security Governance & Compliance: Policy mapping to standards, audit readiness, and regulatory-aligned SecOps.
  • Financial-Sector Cybersecurity: Security engineered for hedge funds and global banks under SEC / OCIE constraints.

Projects

FirewallIQ

AI Firewall Governance & Remediation Platform

A decision system for firewall policy operations: set-math analysis, reachability graphs, and zero-false-deny proofs under strict change governance.

Stack: Python, CIDR / Set Mathematics, Reachability Graphs, RAG, Simulation Engine, SHA-256 Evidence

NAC Coverage Assurance & Endpoint Visibility Platform

Enterprise NAC Coverage Assessment & Endpoint Visibility

Enterprise NAC coverage assessment for Cisco ISE and switch environments: eligible-port analysis, drift detection, and endpoint visibility.

Stack: Python, Cisco ISE, Cisco Switches, 802.1X / MAB, MAC/OUI Profiling, Scheduled Scans, Email Reporting

AI-Driven Security Investigation Platform

LLM platform correlating firewall policy, Cisco ISE logs, and routing data to cut diagnostic latency by 75%.

Stack: Python, LLMs, RAG, LangChain, Cisco ISE, BGP/OSPF

Zero Trust / SASE Architecture for Financial Institutions

Zero Trust and Prisma Access / SASE for large financial environments: least privilege, reduced attack surface, secure remote access.

Stack: Prisma Access, ZTNA, SASE, AI Analytics

Enterprise Firewall Migration Leadership

Led 35+ large-scale firewall migrations across Cisco ASA, Palo Alto, Fortinet, Check Point, Juniper, and Firepower.

Stack: Cisco ASA, Palo Alto, Fortinet, Firepower, Ansible

AI-Native Security Copilot — Nexa Copilot Concept

Security copilot concept: natural-language queries across firewalls, NAC, cloud, and policy with evidence-backed answers.

Stack: RAG, LangGraph, LLMs, Python, Vector Search

Experience

Sr Security Consultant — Point72 Asset Management

Oct 2025 — Present · New York, USA

AI-driven security automation, firewall governance, NAC governance, Zero Trust validation, financial-sector workflows.

  • Built AI-driven security automation using Python, REST APIs, LLMs, RAG, LangChain, and LangGraph to correlate operational data and generate actionable engineering insight.
  • Developed an AI-enabled Palo Alto firewall governance & remediation platform (FirewallIQ) — cut policy review time 60% and improved audit readiness and traceability.
  • Built an enterprise NAC coverage assessment and endpoint visibility platform for Cisco ISE and switch environments — automated eligible-port analysis, drift detection, and remediation gap reporting across thousands of switchports.
  • Operationalized Zero Trust controls via deterministic validation of identity-aware ACLs and microsegmentation — reduced diagnostic latency 75% (45 min → <5 min).
  • Designed a RAG-based Security Intelligence Platform for national financial networks via a secure hub-and-spoke model.

Senior SASE / Zero Trust Consultant — J.P. Morgan & Co.

Jun 2024 — Oct 2025 · Jersey City, USA

Prisma Access, ZTNA, SASE, AI analytics, remote access security for a global financial institution.

  • Designed and deployed Palo Alto Prisma ZTNA to enforce least-privilege access and replace traditional VPN risk.
  • Engineered AI-driven analytics within the SASE architecture — 30% reduction in MTTD and 50% increase in proactive risk mitigation.
  • Built Python / REST API solutions for security automation and real-time log analysis.
  • Led design and execution of a Palo Alto SASE proof-of-concept under strict regulatory and compliance standards.

Senior Security Consulting Engineer — Cisco Systems

Jan 2023 — Apr 2024 · New York, USA

Fortune 100 security architecture, Cisco SASE, Firepower/FTD, ISE, Zero Trust, ransomware remediation.

  • Led customer-facing discovery, architecture, PoC execution, and production deployment for Fortune 100 environments.
  • Implemented ZTNA and microsegmentation with Cisco security solutions to prevent unauthorized lateral movement.
  • Configured Cisco SASE — CASB, ZTNA, and FWaaS — for comprehensive, seamless protection.
  • Directed technical peer reviews, mentored new hires, and delivered HLD/LLD and training curricula.

Senior Network Security Engineer — Altice USA

Mar 2022 — Jan 2023 · New York, USA

Firewall policy, Panorama, Cisco FMC, lab validation, cloud security controls.

  • Leveraged Panorama and Cisco FMC for unified policy enforcement and comprehensive reporting.
  • Applied deep TCP/IP, BGP, OSPF, EIGRP, NAT, and VPN expertise to architect and troubleshoot secure networks.
  • Defined cloud security controls and led on-prem-to-Azure security assessments at enterprise scale.
  • Maintained validation labs with scale, performance, and topology testing using IXIA and SPIRENT.

Security Consulting Engineer — Cisco Systems

Jul 2018 — Jan 2022 · Chicago, USA

Firewall migrations, Python/Ansible automation, Zero Trust remote access, ransomware remediation.

  • Built Python and Ansible automation for rule deployment, migration gap analysis, and compliance checks.
  • Led multi-vendor migrations (Check Point, Juniper, Palo Alto, SonicWall) to Cisco Firepower Threat Defense.
  • Architected emergency Zero Trust remote access for healthcare during COVID-19 — scaled AnyConnect VPN with posture validation (HIPAA).
  • Served as lead technical consultant on Maze ransomware remediation for a Fortune 500 provider.

Network Security Engineer — Northern Trust Corporation

May 2017 — Apr 2018 · Chicago, USA

FirePOWER, Cisco ISE, Gigamon, secure network architecture for banking.

  • Configured FirePOWER 9300 clustered mode and integrated Cisco ISE for automated remediation.
  • Completed Cisco ACS to Cisco ISE 2.2 migrations using automated and manual processes.
  • Deployed Gigamon network security tap and analysis tooling.
  • Validated architecture and design to produce detailed engineering specifications.

Network Security Engineer — Capgemini

Sep 2014 — Dec 2015 · Bengaluru, India

Palo Alto, Cisco ASA, Sourcefire, VPNs, incident/change management, data center security.

  • Configured Palo Alto / Cisco ASA firewalls, zone-based firewalling, and security rules.
  • Managed Sourcefire NGIPS/IDS and analyzed results for threat response.
  • Built site-to-site IPsec VPN tunnels between client and partner sites.
  • Handled incident and change management and data center connectivity troubleshooting.

Books

The Gen AI Security Playbook

Practical Defenses for GenAI Applications

A practitioner's playbook for defending GenAI — covering model risk, secure data pipelines, prompt and context threats, and governance for AI in the enterprise.

View book

Architecting Zero Trust with AI

Modern Zero Trust architecture, AI-augmented

How to design and implement modern Zero Trust architectures augmented with AI — from identity-centric access and microsegmentation to AI-driven detection and response.

View book

AI Awareness for High School Students (upcoming)

Building AI literacy & safety for the next generation

An upcoming book that makes AI literacy, safety, and responsible use accessible to high-school students — covering privacy, security fundamentals, and critical thinking for the AI era.

Research Interests

  • AI Anomaly Detection for Industrial IoT: Resilient, lightweight ML models for real-time anomaly detection on resource-constrained critical-infrastructure hardware.
  • Generative AI × Zero Trust Integration: Embedding GenAI into Zero Trust architectures for endpoint security — supporting SMBs and supply-chain security.
  • Adversarial Training: Hardening AI models against data manipulation and sensor-spoofing attacks through adversarial techniques.
  • Secure AI Data Pipelines: Designing pipelines that protect model integrity and provenance end-to-end across the AI lifecycle.
  • AI Security for SMBs & Supply Chain: Accessible, deployable AI security patterns for smaller organizations and complex supply chains.
  • Lightweight Real-Time Threat Models: Efficient models that enable real-time threat detection and automated response at the edge.

Skills & Tools

AI & Automation

Python, REST APIs, LLMs, RAG, LangChain, LangGraph, AI Agents, Prompt Engineering, Context Engineering, CI/CD

Security Architecture

Zero Trust, SASE, ZTNA, Microsegmentation, Firewall Governance, NAC, IAM, DLP, Incident Response

Vendors & Platforms

Palo Alto, Prisma Access, Cisco ISE, Cisco Firepower/FTD, Cisco SASE, Fortinet, AWS, Azure, Splunk, CrowdStrike, SentinelOne, Tenable

Network Security

TCP/IP, VPN, BGP, OSPF, NAT, IDS/IPS, Proxy, Web Security, Cloud Security Controls

Certifications & Education

  • Cisco Security Core
  • IBM Gen AI Security Professional
  • Azure AZ-500 Security
  • CCNA & CCNP (Security / R&S)
  • PCNSE — Palo Alto
  • AWS Solutions Architect

M.S. in Cybersecurity — DePaul University, Chicago (2018)

Frequently Asked Questions

Who is Digvijay Parmar?

Digvijay Parmar is an AI Security & Zero Trust Architect with 12+ years across Fortune 100 and global financial institutions, building AI-native security automation with RAG, LLMs, and AI agents.

What is FirewallIQ?

FirewallIQ is his flagship firewall policy decision system. It uses IP/CIDR/port set-mathematics and reachability graphs to detect shadowed, duplicate, and redundant rules, and generates zero-false-deny least-privilege proofs under a strict change-governance workflow.

What is the NAC Coverage Assurance Platform?

An enterprise NAC assurance and endpoint visibility platform for Cisco ISE and switch environments. It measures organization-wide 802.1X/MAB coverage, identifies ports missing NAC controls with intelligent eligibility logic, detects configuration drift between scans, and provides endpoint visibility via MAC/vendor profiling.

How can I contact or hire Digvijay?

Use the contact form on this site, email [email protected], or connect on LinkedIn at linkedin.com/in/digvijay-parmar47.

Contact

Email: [email protected]
Phone: +1 312-678-4223
LinkedIn: https://www.linkedin.com/in/digvijay-parmar47/
GitHub: https://github.com/digvijay378