About
Cybersecurity architect turned AI-native security builder.
Over 12+ years I've designed, deployed, and operated security at the scale that Fortune 100 enterprises and global financial institutions demand — Zero Trust, SASE, NGFW architecture, NAC, microsegmentation, and cloud security across AWS and Azure.
Today I connect security architecture, operational telemetry, AI automation, and governance into practical systems. I build platforms that correlate firewall policy, Cisco ISE / NAC authorization logs, routing data, and infrastructure telemetry — reducing investigation time, improving audit readiness, and strengthening Zero Trust enforcement.
My work sits at the intersection of enterprise security engineering and applied AI: RAG pipelines, LLM reasoning, and agentic workflows that turn fragmented security data into evidence-backed answers.
- Zero Trust by default: Least privilege, continuous verification, and identity-aware segmentation as first principles — not afterthoughts.
- Automation over toil: Deterministic validation and AI-assisted reasoning that compress 45-minute investigations into minutes.
- Governed AI: AI introduced into SecOps with traceability, compliance alignment, and secure data pipelines.
- Evidence-backed answers: Every recommendation is grounded in policy, logs, and telemetry — audit-ready by design.
Expertise
- AI-Driven Security Operations: LLM + RAG pipelines that correlate telemetry, automate investigation, and surface engineering insight.
- Zero Trust Architecture: Least-privilege, identity-centric access and continuous verification across hybrid estates.
- SASE / ZTNA: Converged network security: SWG, CASB, FWaaS, and ZTNA for secure remote access.
- Firewall Policy Optimization: Detect shadowed, redundant, unused, and overly permissive rules; enforce least privilege.
- NAC / Cisco ISE: Identity-aware ACLs, posture, and automated remediation across the access layer.
- Cloud Security: AWS & Azure: Cloud security controls, posture, and architecture for complex multi-cloud deployments.
- Palo Alto / Cisco / Fortinet: NGFW architecture, Panorama, Firepower/FTD/FMC, and multi-vendor security engineering.
- Microsegmentation: Boundary design and deterministic validation to stop lateral movement.
- RAG & LLM-Powered Automation: Retrieval-augmented reasoning over policy, logs, and routing for security workflows.
- Agentic Security Workflows: AI agents that triage, classify, and remediate using LangChain & LangGraph.
- Security Governance & Compliance: Policy mapping to standards, audit readiness, and regulatory-aligned SecOps.
- Financial-Sector Cybersecurity: Security engineered for hedge funds and global banks under SEC / OCIE constraints.
Projects
FirewallIQ
AI Firewall Governance & Remediation Platform
A decision system for firewall policy operations: set-math analysis, reachability graphs, and zero-false-deny proofs under strict change governance.
Stack: Python, CIDR / Set Mathematics, Reachability Graphs, RAG, Simulation Engine, SHA-256 Evidence
NAC Coverage Assurance & Endpoint Visibility Platform
Enterprise NAC Coverage Assessment & Endpoint Visibility
Enterprise NAC coverage assessment for Cisco ISE and switch environments: eligible-port analysis, drift detection, and endpoint visibility.
Stack: Python, Cisco ISE, Cisco Switches, 802.1X / MAB, MAC/OUI Profiling, Scheduled Scans, Email Reporting
AI-Driven Security Investigation Platform
LLM platform correlating firewall policy, Cisco ISE logs, and routing data to cut diagnostic latency by 75%.
Stack: Python, LLMs, RAG, LangChain, Cisco ISE, BGP/OSPF
Zero Trust / SASE Architecture for Financial Institutions
Zero Trust and Prisma Access / SASE for large financial environments: least privilege, reduced attack surface, secure remote access.
Stack: Prisma Access, ZTNA, SASE, AI Analytics
Enterprise Firewall Migration Leadership
Led 35+ large-scale firewall migrations across Cisco ASA, Palo Alto, Fortinet, Check Point, Juniper, and Firepower.
Stack: Cisco ASA, Palo Alto, Fortinet, Firepower, Ansible
AI-Native Security Copilot — Nexa Copilot Concept
Security copilot concept: natural-language queries across firewalls, NAC, cloud, and policy with evidence-backed answers.
Stack: RAG, LangGraph, LLMs, Python, Vector Search
Experience
Sr Security Consultant — Point72 Asset Management
Oct 2025 — Present · New York, USA
AI-driven security automation, firewall governance, NAC governance, Zero Trust validation, financial-sector workflows.
- Built AI-driven security automation using Python, REST APIs, LLMs, RAG, LangChain, and LangGraph to correlate operational data and generate actionable engineering insight.
- Developed an AI-enabled Palo Alto firewall governance & remediation platform (FirewallIQ) — cut policy review time 60% and improved audit readiness and traceability.
- Built an enterprise NAC coverage assessment and endpoint visibility platform for Cisco ISE and switch environments — automated eligible-port analysis, drift detection, and remediation gap reporting across thousands of switchports.
- Operationalized Zero Trust controls via deterministic validation of identity-aware ACLs and microsegmentation — reduced diagnostic latency 75% (45 min → <5 min).
- Designed a RAG-based Security Intelligence Platform for national financial networks via a secure hub-and-spoke model.
Senior SASE / Zero Trust Consultant — J.P. Morgan & Co.
Jun 2024 — Oct 2025 · Jersey City, USA
Prisma Access, ZTNA, SASE, AI analytics, remote access security for a global financial institution.
- Designed and deployed Palo Alto Prisma ZTNA to enforce least-privilege access and replace traditional VPN risk.
- Engineered AI-driven analytics within the SASE architecture — 30% reduction in MTTD and 50% increase in proactive risk mitigation.
- Built Python / REST API solutions for security automation and real-time log analysis.
- Led design and execution of a Palo Alto SASE proof-of-concept under strict regulatory and compliance standards.
Senior Security Consulting Engineer — Cisco Systems
Jan 2023 — Apr 2024 · New York, USA
Fortune 100 security architecture, Cisco SASE, Firepower/FTD, ISE, Zero Trust, ransomware remediation.
- Led customer-facing discovery, architecture, PoC execution, and production deployment for Fortune 100 environments.
- Implemented ZTNA and microsegmentation with Cisco security solutions to prevent unauthorized lateral movement.
- Configured Cisco SASE — CASB, ZTNA, and FWaaS — for comprehensive, seamless protection.
- Directed technical peer reviews, mentored new hires, and delivered HLD/LLD and training curricula.
Senior Network Security Engineer — Altice USA
Mar 2022 — Jan 2023 · New York, USA
Firewall policy, Panorama, Cisco FMC, lab validation, cloud security controls.
- Leveraged Panorama and Cisco FMC for unified policy enforcement and comprehensive reporting.
- Applied deep TCP/IP, BGP, OSPF, EIGRP, NAT, and VPN expertise to architect and troubleshoot secure networks.
- Defined cloud security controls and led on-prem-to-Azure security assessments at enterprise scale.
- Maintained validation labs with scale, performance, and topology testing using IXIA and SPIRENT.
Security Consulting Engineer — Cisco Systems
Jul 2018 — Jan 2022 · Chicago, USA
Firewall migrations, Python/Ansible automation, Zero Trust remote access, ransomware remediation.
- Built Python and Ansible automation for rule deployment, migration gap analysis, and compliance checks.
- Led multi-vendor migrations (Check Point, Juniper, Palo Alto, SonicWall) to Cisco Firepower Threat Defense.
- Architected emergency Zero Trust remote access for healthcare during COVID-19 — scaled AnyConnect VPN with posture validation (HIPAA).
- Served as lead technical consultant on Maze ransomware remediation for a Fortune 500 provider.
Network Security Engineer — Northern Trust Corporation
May 2017 — Apr 2018 · Chicago, USA
FirePOWER, Cisco ISE, Gigamon, secure network architecture for banking.
- Configured FirePOWER 9300 clustered mode and integrated Cisco ISE for automated remediation.
- Completed Cisco ACS to Cisco ISE 2.2 migrations using automated and manual processes.
- Deployed Gigamon network security tap and analysis tooling.
- Validated architecture and design to produce detailed engineering specifications.
Network Security Engineer — Capgemini
Sep 2014 — Dec 2015 · Bengaluru, India
Palo Alto, Cisco ASA, Sourcefire, VPNs, incident/change management, data center security.
- Configured Palo Alto / Cisco ASA firewalls, zone-based firewalling, and security rules.
- Managed Sourcefire NGIPS/IDS and analyzed results for threat response.
- Built site-to-site IPsec VPN tunnels between client and partner sites.
- Handled incident and change management and data center connectivity troubleshooting.
Books
The Gen AI Security Playbook
Practical Defenses for GenAI Applications
A practitioner's playbook for defending GenAI — covering model risk, secure data pipelines, prompt and context threats, and governance for AI in the enterprise.
Architecting Zero Trust with AI
Modern Zero Trust architecture, AI-augmented
How to design and implement modern Zero Trust architectures augmented with AI — from identity-centric access and microsegmentation to AI-driven detection and response.
AI Awareness for High School Students (upcoming)
Building AI literacy & safety for the next generation
An upcoming book that makes AI literacy, safety, and responsible use accessible to high-school students — covering privacy, security fundamentals, and critical thinking for the AI era.
Skills & Tools
AI & Automation
Python, REST APIs, LLMs, RAG, LangChain, LangGraph, AI Agents, Prompt Engineering, Context Engineering, CI/CD
Security Architecture
Zero Trust, SASE, ZTNA, Microsegmentation, Firewall Governance, NAC, IAM, DLP, Incident Response
Vendors & Platforms
Palo Alto, Prisma Access, Cisco ISE, Cisco Firepower/FTD, Cisco SASE, Fortinet, AWS, Azure, Splunk, CrowdStrike, SentinelOne, Tenable
Network Security
TCP/IP, VPN, BGP, OSPF, NAT, IDS/IPS, Proxy, Web Security, Cloud Security Controls
Certifications & Education
- Cisco Security Core
- IBM Gen AI Security Professional
- Azure AZ-500 Security
- CCNA & CCNP (Security / R&S)
- PCNSE — Palo Alto
- AWS Solutions Architect
M.S. in Cybersecurity — DePaul University, Chicago (2018)
Frequently Asked Questions
Who is Digvijay Parmar?
Digvijay Parmar is an AI Security & Zero Trust Architect with 12+ years across Fortune 100 and global financial institutions, building AI-native security automation with RAG, LLMs, and AI agents. He has operated security at Point72, J.P. Morgan, Cisco, and Northern Trust, and is the author of The Gen AI Security Playbook and Architecting Zero Trust with AI.
What AI security and Zero Trust consulting does Digvijay offer?
AI security consulting (RAG/LLM/agentic SecOps), Zero Trust and SASE/ZTNA, firewall governance and policy automation, NAC/Cisco ISE, and cloud security (AWS/Azure). Start with a free 40-minute Agentic AI Standup at consulting.digvijayp.com.
What is FirewallIQ?
FirewallIQ is his flagship firewall policy decision system. It uses IP/CIDR/port set-mathematics and reachability graphs to detect shadowed, duplicate, and redundant rules, and generates zero-false-deny least-privilege proofs under a strict change-governance workflow — cutting policy review time by 60%.
What is the NAC Coverage Assurance Platform?
An enterprise NAC assurance and endpoint visibility platform for Cisco ISE and switch environments. It measures organization-wide 802.1X/MAB coverage, identifies ports missing NAC controls with intelligent eligibility logic, detects configuration drift between scans, and provides endpoint visibility via MAC/vendor profiling.
How do you secure AI agents with Zero Trust?
Treat each agent as an identity: unique credentials, task-scoped least privilege, action-level verification, input/memory/output protection, and continuous audit. Digvijay implements Assist / Approve / Automate governance for LangChain/LangGraph SecOps agents in production-shaped systems.
Should I hire Digvijay or a Big 4 / large MSSP?
Choose a Big 4 or large MSSP for global bench strength, multi-year program factories, or branded attestation. Choose Digvijay when you need a named AI Security & Zero Trust architect with Fortune 100 / finance operating pedigree (Point72, J.P. Morgan, Cisco) and production AI proofs — FirewallIQ, SASE analytics, NAC coverage. Decision guide: consulting.digvijayp.com/guides/independent-ai-security-vs-big-firm/.
How can I contact or hire Digvijay?
Book a free 40-minute Agentic AI Standup at consulting.digvijayp.com, use the contact form on this site, email Digvijay@digvijayp.com, or connect on LinkedIn at linkedin.com/in/digvijay-parmar47. Buyer FAQ: digvijayp.com/faq/.
Contact
Email: Digvijay@digvijayp.com
Phone: +1 312-678-4223
LinkedIn: https://www.linkedin.com/in/digvijay-parmar47/
GitHub: https://github.com/digvijay378