AI Security & Zero Trust Architect

Building AI-Native Security Systems for the Identity-First Enterprise.

AI security and Zero Trust consulting for Fortune 100 and global financial institutions — SASE/ZTNA, firewall governance, Cisco ISE/NAC, and governed AI agents with measurable SecOps outcomes.

New Jersey, USA · [email protected] · LinkedIn · GitHub

About

Cybersecurity architect turned AI-native security builder.

Over 12+ years I've designed, deployed, and operated security at the scale that Fortune 100 enterprises and global financial institutions demand — Zero Trust, SASE, NGFW architecture, NAC, microsegmentation, and cloud security across AWS and Azure.

Today I connect security architecture, operational telemetry, AI automation, and governance into practical systems. I build platforms that correlate firewall policy, Cisco ISE / NAC authorization logs, routing data, and infrastructure telemetry — reducing investigation time, improving audit readiness, and strengthening Zero Trust enforcement.

My work sits at the intersection of enterprise security engineering and applied AI: RAG pipelines, LLM reasoning, and agentic workflows that turn fragmented security data into evidence-backed answers.

  • Zero Trust by default: Least privilege, continuous verification, and identity-aware segmentation as first principles — not afterthoughts.
  • Automation over toil: Deterministic validation and AI-assisted reasoning that compress 45-minute investigations into minutes.
  • Governed AI: AI introduced into SecOps with traceability, compliance alignment, and secure data pipelines.
  • Evidence-backed answers: Every recommendation is grounded in policy, logs, and telemetry — audit-ready by design.

Expertise

  • AI-Driven Security Operations: LLM + RAG pipelines that correlate telemetry, automate investigation, and surface engineering insight.
  • Zero Trust Architecture: Least-privilege, identity-centric access and continuous verification across hybrid estates.
  • SASE / ZTNA: Converged network security: SWG, CASB, FWaaS, and ZTNA for secure remote access.
  • Firewall Policy Optimization: Detect shadowed, redundant, unused, and overly permissive rules; enforce least privilege.
  • NAC / Cisco ISE: Identity-aware ACLs, posture, and automated remediation across the access layer.
  • Cloud Security: AWS & Azure: Cloud security controls, posture, and architecture for complex multi-cloud deployments.
  • Palo Alto / Cisco / Fortinet: NGFW architecture, Panorama, Firepower/FTD/FMC, and multi-vendor security engineering.
  • Microsegmentation: Boundary design and deterministic validation to stop lateral movement.
  • RAG & LLM-Powered Automation: Retrieval-augmented reasoning over policy, logs, and routing for security workflows.
  • Agentic Security Workflows: AI agents that triage, classify, and remediate using LangChain & LangGraph.
  • Security Governance & Compliance: Policy mapping to standards, audit readiness, and regulatory-aligned SecOps.
  • Financial-Sector Cybersecurity: Security engineered for hedge funds and global banks under SEC / OCIE constraints.

Projects

FirewallIQ

AI Firewall Governance & Remediation Platform

A decision system for firewall policy operations: set-math analysis, reachability graphs, and zero-false-deny proofs under strict change governance.

Stack: Python, CIDR / Set Mathematics, Reachability Graphs, RAG, Simulation Engine, SHA-256 Evidence

NAC Coverage Assurance & Endpoint Visibility Platform

Enterprise NAC Coverage Assessment & Endpoint Visibility

Enterprise NAC coverage assessment for Cisco ISE and switch environments: eligible-port analysis, drift detection, and endpoint visibility.

Stack: Python, Cisco ISE, Cisco Switches, 802.1X / MAB, MAC/OUI Profiling, Scheduled Scans, Email Reporting

AI-Driven Security Investigation Platform

LLM platform correlating firewall policy, Cisco ISE logs, and routing data to cut diagnostic latency by 75%.

Stack: Python, LLMs, RAG, LangChain, Cisco ISE, BGP/OSPF

Zero Trust / SASE Architecture for Financial Institutions

Zero Trust and Prisma Access / SASE for large financial environments: least privilege, reduced attack surface, secure remote access.

Stack: Prisma Access, ZTNA, SASE, AI Analytics

Enterprise Firewall Migration Leadership

Led 35+ large-scale firewall migrations across Cisco ASA, Palo Alto, Fortinet, Check Point, Juniper, and Firepower.

Stack: Cisco ASA, Palo Alto, Fortinet, Firepower, Ansible

AI-Native Security Copilot — Nexa Copilot Concept

Security copilot concept: natural-language queries across firewalls, NAC, cloud, and policy with evidence-backed answers.

Stack: RAG, LangGraph, LLMs, Python, Vector Search

Experience

Sr Security Consultant — Point72 Asset Management

Oct 2025 — Present · New York, USA

AI-driven security automation, firewall governance, NAC governance, Zero Trust validation, financial-sector workflows.

  • Built AI-driven security automation using Python, REST APIs, LLMs, RAG, LangChain, and LangGraph to correlate operational data and generate actionable engineering insight.
  • Developed an AI-enabled Palo Alto firewall governance & remediation platform (FirewallIQ) — cut policy review time 60% and improved audit readiness and traceability.
  • Built an enterprise NAC coverage assessment and endpoint visibility platform for Cisco ISE and switch environments — automated eligible-port analysis, drift detection, and remediation gap reporting across thousands of switchports.
  • Operationalized Zero Trust controls via deterministic validation of identity-aware ACLs and microsegmentation — reduced diagnostic latency 75% (45 min → <5 min).
  • Designed a RAG-based Security Intelligence Platform for national financial networks via a secure hub-and-spoke model.

Senior SASE / Zero Trust Consultant — J.P. Morgan & Co.

Jun 2024 — Oct 2025 · Jersey City, USA

Prisma Access, ZTNA, SASE, AI analytics, remote access security for a global financial institution.

  • Designed and deployed Palo Alto Prisma ZTNA to enforce least-privilege access and replace traditional VPN risk.
  • Engineered AI-driven analytics within the SASE architecture — 30% reduction in MTTD and 50% increase in proactive risk mitigation.
  • Built Python / REST API solutions for security automation and real-time log analysis.
  • Led design and execution of a Palo Alto SASE proof-of-concept under strict regulatory and compliance standards.

Senior Security Consulting Engineer — Cisco Systems

Jan 2023 — Apr 2024 · New York, USA

Fortune 100 security architecture, Cisco SASE, Firepower/FTD, ISE, Zero Trust, ransomware remediation.

  • Led customer-facing discovery, architecture, PoC execution, and production deployment for Fortune 100 environments.
  • Implemented ZTNA and microsegmentation with Cisco security solutions to prevent unauthorized lateral movement.
  • Configured Cisco SASE — CASB, ZTNA, and FWaaS — for comprehensive, seamless protection.
  • Directed technical peer reviews, mentored new hires, and delivered HLD/LLD and training curricula.

Senior Network Security Engineer — Altice USA

Mar 2022 — Jan 2023 · New York, USA

Firewall policy, Panorama, Cisco FMC, lab validation, cloud security controls.

  • Leveraged Panorama and Cisco FMC for unified policy enforcement and comprehensive reporting.
  • Applied deep TCP/IP, BGP, OSPF, EIGRP, NAT, and VPN expertise to architect and troubleshoot secure networks.
  • Defined cloud security controls and led on-prem-to-Azure security assessments at enterprise scale.
  • Maintained validation labs with scale, performance, and topology testing using IXIA and SPIRENT.

Security Consulting Engineer — Cisco Systems

Jul 2018 — Jan 2022 · Chicago, USA

Firewall migrations, Python/Ansible automation, Zero Trust remote access, ransomware remediation.

  • Built Python and Ansible automation for rule deployment, migration gap analysis, and compliance checks.
  • Led multi-vendor migrations (Check Point, Juniper, Palo Alto, SonicWall) to Cisco Firepower Threat Defense.
  • Architected emergency Zero Trust remote access for healthcare during COVID-19 — scaled AnyConnect VPN with posture validation (HIPAA).
  • Served as lead technical consultant on Maze ransomware remediation for a Fortune 500 provider.

Network Security Engineer — Northern Trust Corporation

May 2017 — Apr 2018 · Chicago, USA

FirePOWER, Cisco ISE, Gigamon, secure network architecture for banking.

  • Configured FirePOWER 9300 clustered mode and integrated Cisco ISE for automated remediation.
  • Completed Cisco ACS to Cisco ISE 2.2 migrations using automated and manual processes.
  • Deployed Gigamon network security tap and analysis tooling.
  • Validated architecture and design to produce detailed engineering specifications.

Network Security Engineer — Capgemini

Sep 2014 — Dec 2015 · Bengaluru, India

Palo Alto, Cisco ASA, Sourcefire, VPNs, incident/change management, data center security.

  • Configured Palo Alto / Cisco ASA firewalls, zone-based firewalling, and security rules.
  • Managed Sourcefire NGIPS/IDS and analyzed results for threat response.
  • Built site-to-site IPsec VPN tunnels between client and partner sites.
  • Handled incident and change management and data center connectivity troubleshooting.

Books

The Gen AI Security Playbook

Practical Defenses for GenAI Applications

A practitioner's playbook for defending GenAI — covering model risk, secure data pipelines, prompt and context threats, and governance for AI in the enterprise.

View book

Architecting Zero Trust with AI

Modern Zero Trust architecture, AI-augmented

How to design and implement modern Zero Trust architectures augmented with AI — from identity-centric access and microsegmentation to AI-driven detection and response.

View book

AI Awareness for High School Students (upcoming)

Building AI literacy & safety for the next generation

An upcoming book that makes AI literacy, safety, and responsible use accessible to high-school students — covering privacy, security fundamentals, and critical thinking for the AI era.

Skills & Tools

AI & Automation

Python, REST APIs, LLMs, RAG, LangChain, LangGraph, AI Agents, Prompt Engineering, Context Engineering, CI/CD

Security Architecture

Zero Trust, SASE, ZTNA, Microsegmentation, Firewall Governance, NAC, IAM, DLP, Incident Response

Vendors & Platforms

Palo Alto, Prisma Access, Cisco ISE, Cisco Firepower/FTD, Cisco SASE, Fortinet, AWS, Azure, Splunk, CrowdStrike, SentinelOne, Tenable

Network Security

TCP/IP, VPN, BGP, OSPF, NAT, IDS/IPS, Proxy, Web Security, Cloud Security Controls

Certifications & Education

  • Cisco Security Core
  • IBM Gen AI Security Professional
  • Azure AZ-500 Security
  • CCNA & CCNP (Security / R&S)
  • PCNSE — Palo Alto
  • AWS Solutions Architect

M.S. in Cybersecurity — DePaul University, Chicago (2018)

Frequently Asked Questions

Who is Digvijay Parmar?

Digvijay Parmar is an AI Security & Zero Trust Architect with 12+ years across Fortune 100 and global financial institutions, building AI-native security automation with RAG, LLMs, and AI agents. He has operated security at Point72, J.P. Morgan, Cisco, and Northern Trust, and is the author of The Gen AI Security Playbook and Architecting Zero Trust with AI.

What AI security and Zero Trust consulting does Digvijay offer?

AI security consulting (RAG/LLM/agentic SecOps), Zero Trust and SASE/ZTNA, firewall governance and policy automation, NAC/Cisco ISE, and cloud security (AWS/Azure). Start with a free 40-minute Agentic AI Standup at consulting.digvijayp.com.

What is FirewallIQ?

FirewallIQ is his flagship firewall policy decision system. It uses IP/CIDR/port set-mathematics and reachability graphs to detect shadowed, duplicate, and redundant rules, and generates zero-false-deny least-privilege proofs under a strict change-governance workflow — cutting policy review time by 60%.

What is the NAC Coverage Assurance Platform?

An enterprise NAC assurance and endpoint visibility platform for Cisco ISE and switch environments. It measures organization-wide 802.1X/MAB coverage, identifies ports missing NAC controls with intelligent eligibility logic, detects configuration drift between scans, and provides endpoint visibility via MAC/vendor profiling.

How do you secure AI agents with Zero Trust?

Treat each agent as an identity: unique credentials, task-scoped least privilege, action-level verification, input/memory/output protection, and continuous audit. Digvijay implements Assist / Approve / Automate governance for LangChain/LangGraph SecOps agents in production-shaped systems.

Should I hire Digvijay or a Big 4 / large MSSP?

Choose a Big 4 or large MSSP for global bench strength, multi-year program factories, or branded attestation. Choose Digvijay when you need a named AI Security & Zero Trust architect with Fortune 100 / finance operating pedigree (Point72, J.P. Morgan, Cisco) and production AI proofs — FirewallIQ, SASE analytics, NAC coverage. Decision guide: consulting.digvijayp.com/guides/independent-ai-security-vs-big-firm/.

How can I contact or hire Digvijay?

Book a free 40-minute Agentic AI Standup at consulting.digvijayp.com, use the contact form on this site, email [email protected], or connect on LinkedIn at linkedin.com/in/digvijay-parmar47. Buyer FAQ: digvijayp.com/faq/.

Contact

Email: [email protected]
Phone: +1 312-678-4223
LinkedIn: https://www.linkedin.com/in/digvijay-parmar47/
GitHub: https://github.com/digvijay378