Skip to main content
Aaron Stovall 32.64°N · 117.08°W · Chula Vista, CA
Network Security Engineer · Chula Vista, California

Aaron Stovall

Defending enterprise networks, building the tooling to run them.

// 15 yrs · panorama & check point MDM · agentic automation

Fifteen years inside the firewall estates of global manufacturers, a hyperscale social platform, and a pediatric hospital, with deep Palo Alto Panorama and Check Point Multi-Domain practice, and equally a builder shipping production Rust, TypeScript, and Go platforms that turn firewall operations into automated, self-service workflows.

Focus
Palo Alto · Check Point · Cisco
Builds in
Rust · TypeScript · Go
Compliance
NIST · CIS · ISO 27001
Profile

Network security engineer with fifteen years spent inside the firewall estates of global manufacturers, a hyperscale social platform, and a pediatric hospital, with deep Palo Alto Panorama and Check Point Multi-Domain practice across thousands of HA-configured devices, layered over Cisco Catalyst, Nexus, Meraki, ISE, and Aruba.

15+
Years Experience
70+
Automated Features
40%
Less Manual Work
20%
Faster Response
100%
Audit Adherence

Selected Impact

Global firewall operations
Ran Palo Alto Panorama and Check Point Multi-Domain estates across global operations, cutting incident response time 20% through centralized policy management and automation.
Automation at scale
Removed 40% of manual operational work via Python and Ansible pipelines, then extended past scripting into production-grade Rust and TypeScript platforms.
Agentic infrastructure automation
Designs agentic, AI-assisted automation for multi-vendor network operations, pairing natural-language intent with deterministic, governed execution.
Platform development
Built full-stack network management and analysis platforms integrating Palo Alto, Cisco, and Juniper APIs into unified control planes.
M&A security integration
Led perimeter assessments and site integrations across mergers, acquisitions, and divestitures, standardizing the work into repeatable playbooks.
Tier 3 escalation
Resolved hundreds of cross-domain escalations spanning routing, switching, firewall policy, wireless, and VPN in 24/7 production environments.
Compliance & zero trust
Held 100% audit adherence across NIST, CIS, CISA, and ISO 27001, embedding least-privilege enforcement into policy, access control, and segmentation.
Education & Credentials
Bachelor of Science, Game Software Development Westwood College, Upland, CA · 2005 – 2009
Palo Alto Networks Certified Network Security Engineer (PCNSE) Renewal in progress
Cisco Certified Network Associate (CCNA) Previously held
Experience

Eight roles across six organizations over fifteen years, progressing from helpdesk and field operations into senior network security engineering and platform development.

  1. Oct 2025 – Feb 2026

    Insight Global

    Network Engineer
    70+ automated featuresPA-7080 · PA-5400 fleetHIPAA-governed
    • Ran firewall request fulfillment, policy troubleshooting, and traffic analysis across a Panorama-managed HA estate of PA-7080 and PA-5400 firewalls in a HIPAA-governed healthcare environment.
    • Built the CNTRL platform, unifying Palo Alto Panorama, Cisco ISE, Catalyst Center, and Juniper Mist APIs into one control plane with 70+ automated features spanning policy hygiene, rule-overlap detection, compliance, and traffic analysis.
    • Developed Palo Alto API tooling for policy validation, operational dashboards, PAN-OS lifecycle management, upgrade automation, and visual log analysis.
    • Automated Cisco Catalyst Center and Nexus operations through platform APIs and direct SSH.
    • Designed and still supports SYDONIC, his own model-independent agent engineering environment: a deterministic Rust kernel owning durable mission state, multi-provider model routing, governed memory, capability grants, and replay-safe evidence.
  2. Nov 2024 – Oct 2025

    Mythos Systems

    Principal Network Security Engineer & Automation Developer
    Rust (Tauri 2) + SvelteKit115+ diagnostic scenariosPost-quantum crypto
    • Shipped a portfolio of production-grade network security and automation platforms in Rust (Tauri 2.0) and SvelteKit, converting years of firewall operations experience into tooling that removes manual effort and shortens incident resolution.
    • Architected API-driven integrations across Palo Alto Panorama, Cisco Catalyst Center, and Cisco ISE, automating policy hygiene, compliance, blast-radius assessment, and 115+ diagnostic scenarios that previously demanded manual CLI work.
    • Current work centers on a custom agentic framework for network operations: natural-language request interpretation, an integrated LLM with hybrid RAG retrieval over Palo Alto, Cisco, and Juniper documentation, and controlled, citation-backed execution.
    • Engineered post-quantum secure communications across the stack using Open Quantum Safe cryptography, including Kyber key exchange, Dilithium signatures, and quantum-safe TLS.
    • Cut firewall and VPN triage from hours to minutes by parallelizing 60+ diagnostic commands with anomaly detection and TAC-ready reporting.
  3. Jun 2022 – Nov 2024

    TikTok (ByteDance)

    Sr. Business Operations Protection Specialist, Network Security
    20% faster resolution30% posture gain40% less manual work
    • Directed daily operations for a global Panorama-managed HA environment of PA-5200, PA-3000, and PA-1400 firewalls alongside Cisco Meraki and Nexus switching, improving resolution times 20% through proactive automation.
    • Engineered multi-cloud network security across Azure and Oracle Cloud, lifting security posture 30% via automation-driven deployment and threat modeling in Python and Rust.
    • Provisioned and managed Palo Alto firewalls and Panorama in Azure using Terraform, configuring network security groups, peering, and policy sets to extend on-premises architecture into the cloud.
    • Built a custom Ansible Tower environment that cut manual provisioning effort 40% and made deployments repeatable at scale.
    • Deployed and managed ByteWAF and Akamai WAF via Istio service mesh, configuring rulesets and monitoring threats across web services in the USDS enclave.
  4. Nov 2011 – Jun 2022

    TE Connectivity

    Network Security Engineer III Mar 2021 – Jun 2022
    6,000-device refreshCheck Point MDMSZero-trust ZIA/ZPA
    • Managed global firewall operations across a Check Point Multi-Domain Management System spanning thousands of HA-configured firewalls, leading site security integrations and posture reviews through M&A activity.
    • Wrote a Python application automating Check Point firewall onboarding, imaging, policy provisioning, health checks, and log analysis for a 6,000-device refresh.
    • Built policy validation tooling on the Check Point Management API, scanning configurations across domains for rule violations, shadowed rules, and untracked access.
    • Administered Zscaler ZIA and ZPA, managing app connectors, access policies, and traffic forwarding for zero-trust connectivity across remote users and branch sites.
    • Coordinated multi-domain change management globally, holding policy consistency and compliance validation through M&A integrations and refresh cycles.
    Information Security Engineer III Jan 2019 – Mar 2021
    15% faster delivery10% fewer incidents24/7 on-call
    • Ran daily operations on Check Point MDMS firewalls across thousands of HA-configured devices: security requests, policy changes, HA failover validation, and M&A site integrations.
    • Processed policy updates, imaging requests, and health check validation, holding configuration standards and security baselines through maintenance windows.
    • Audited firewall configurations for policy violations and untracked access, driving remediation through targeted rule updates and change management.
    • Partnered with the Cyber Security team on incident response workflows and organizational security objectives.
    • Improved project delivery timelines 15% through Python and Rust automation of configuration updates and policy validation.
    IT Operations Analyst III Nov 2011 – Jan 2019
    Aruba wireless SMEFounded dev team35–45% on-site
    • Oversaw multi-site IT operations across West Coast facilities: upgrades, greenfield deployments, and on-site security integrations spanning Cisco Catalyst, Nexus, and Check Point. On-site work ran 35–45% of the role.
    • Served as subject matter expert for Aruba wireless, managing controllers, access point deployments, RF tuning, and role-based access policy.
    • Managed vendor and contractor relationships for infrastructure procurement, covering UPS systems, racks, network closets, AV systems, and gigabit Ethernet installations.
    • Evolved the team’s DevOps standards to include development standards, and established a small development team building Python and Rust network automation.
    • Partnered across Facilities, IT, and HR to support scalable, secure growth through process automation and consistent policy enforcement.
  5. Apr 2010 – Nov 2011

    Deutsch Industrial Products

    Helpdesk Administrator
    • Provided helpdesk administration and network support across the organization, handling user support and system troubleshooting.
  6. Feb 2009 – Apr 2010

    Ramko Manufacturing

    Network Administrator
    • Managed network administration, user support, and multi-site infrastructure.
Capabilities

Two ways to read this chapter: the disciplines Aaron operates across, and the concrete toolchain behind them.

Disciplines

Security
Palo Alto NGFW & Panorama·Check Point MDMS·Fortinet·Zscaler ZIA/ZPA·WAF·IDS/IPS·Zero Trust·Segmentation·Threat modeling
Network
Cisco Catalyst, Nexus, Meraki·Cisco ISE 802.1X·Aruba wireless·SD-WAN·LAN/WAN·Routing & switching·Tier 3 troubleshooting
Automation
Python·Ansible & Tower/AWX·Terraform·REST API orchestration·CI/CD·Infrastructure as code
Development
Rust (Axum, Tauri)·TypeScript·SvelteKit·Python (Django, Flask)·Agentic frameworks·LLM/RAG integration

Toolchain

Languages
  • Rust
  • TypeScript
  • Go
  • Python
Automation & IaC
  • Ansible & Tower/AWX
  • Terraform
  • CI/CD
  • SYDONIC
Platforms & APIs
  • Palo Alto Panorama
  • Check Point MDMS
  • Cisco Catalyst Center
  • NetBox
  • Infoblox
Operations
  • Zero Trust
  • Threat Modeling
  • ServiceNow
  • Jira
  • Observability

A 90+ mastery B 80–89 advanced C working proficiency

Selected Work

Product development under Mythos Systems that grew in generations: focused operational tools, vendor-specific platforms, cross-vendor control planes, and now governed intelligent systems. Below are the platforms in flight, the shipped desktop applications built in Rust and SvelteKit, and the lineage that produced them.

Current work · in flight

Active development

PANTHEON

Governed agentic engineering platform

The flagship Mythos Systems platform: a natural-language environment for software, network, and security engineering where human intent becomes typed, reviewable plans. Models and agents interpret and propose; deterministic tools execute approved actions under policy, simulation, validation, and immutable evidence.

Rust · Tokio · Tauri 2 · Svelte 5 · Python · MCP · Tree-sitter · Monaco · OpenTelemetry

Implementation candidate

SYDONIC

Model-independent agent engineering environment

A standalone, Windows-first agent engineering environment where no model, IDE, or provider is ever authoritative. The Rust daemon sydonicd is the sole owner of durable state transitions: a deterministic agent kernel, missions and work orders, multi-provider model routing, governed memory, capability grants and budgets, out-of-process execution, and replay-safe evidence. CLI, TUI, IDE, SDK, and PANTHEON attach as equal protocol clients.

Rust 2024 · Tokio · SQLite WAL · Protobuf · gRPC · Job Objects · content-addressed artifacts · OpenTelemetry

Pre-Phase-0 blueprint

LABYRINTH

Network automation, reconciliation & assurance

A NetBox-centered platform for telecom, fiber, and enterprise networks where intended state, observed state, and business context are continuously reconciled. Admission control, blast-radius scoring, maintenance windows, digital-twin simulation, canary execution, postchecks, rollback, and immutable evidence gate every change.

Rust · Axum · Nornir · Batfish · containerlab · NATS JetStream · PostgreSQL · ClickHouse · GitOps · Tauri 2

Foundation architecture

CALLISTO

Privacy-first browser & secure web workspace

A Rust-first desktop browser built as a secure operating environment for modern web work: identity profiles and durable workspaces, privacy enforcement by default, a native VPN and credential vault, signed capability modules, and integrated AI assistance through Ask Callisto.

Rust · Tauri 2 · SvelteKit · wgpu · Vello · WireGuard · signed modules · native messaging · PQ research

Active program

MYTHOS AI

Applied AI research, benchmarking & assurance

The program that defines how Mythos Systems selects, evaluates, secures, governs, and validates AI systems: agentic runtimes, model lifecycle governance, evaluation harnesses, adversarial testing, context engineering, memory, tool authorization, and local-first inference. Model output is treated as a proposal, never authoritative state.

Python evaluation harnesses · Rust/TS reference systems · MCP · retrieval & vector systems · benchmark suites · signed evidence

Shipped desktop platforms

2024 – Present

VERTEX

Palo Alto Command & Control Platform

Native desktop application built for network engineers and security operations teams managing enterprise Palo Alto Networks firewall infrastructure at scale. Built with Tauri 2 (Rust backend + SvelteKit 5 frontend), it ships as a lightweight, browser-free binary for Windows and macOS. The platform consolidates what would typically require dozens of separate tools into a single unified interface.

  • Eklipse Real-Time Telemetry Real-time firewall telemetry monitoring (CPU, memory, sessions, throughput) across multiple devices with threshold-based alerting.
  • Omnis Predictive Monitoring Predictive monitoring with SSH-based telemetry collection and anomaly detection across the managed firewall fleet.
  • PA-DIAG Diagnostics Engine Automated diagnostics engine with 115+ troubleshooting scenarios across 46 diagnostic categories, with PDF/DOCX/Excel/JSON report generation.
RustTauri 2.0SvelteKitTypeScriptPalo Alto API
2024 – Present

PRISM

Cisco Catalyst Intelligence Platform

Windows desktop application built with Tauri (Rust backend) and SvelteKit/Svelte 5 (frontend) designed for network engineers managing large-scale Cisco Catalyst switching infrastructure. Connects to Cisco Catalyst Center via REST API and to individual network devices via SSH and serial console.

  • Helix Terminal Manager Multi-tab SSH terminal manager with device inventory, command snippets, config pull, session logging, and serial console support.
  • Exception Report ISE 802.1X compliance analysis across all switch ports, with per-port compliance scoring, heatmaps, remediation, and rollback.
  • Config Analysis SSH-based configuration compliance checking against customizable rule templates covering security, best practices, QoS, STP, SNMP, and NTP.
RustTauri 2.0SvelteKitTypeScriptCatalyst Center API
2024 – Present

GHOSTWAVE

Wireless Analysis & Security Auditing Platform

Cross-platform desktop wireless network analysis and security auditing platform. Built with Tauri 2 (Rust backend) and SvelteKit (frontend), it provides a comprehensive suite of tools for Wi-Fi infrastructure management, from network scanning and RF analysis to security auditing and compliance reporting.

  • Security Auditing WPA3 transition scoring, PMF auditing, credential analysis, PCI compliance checks, and rogue AP classification.
  • RF Spectrum Analysis Waterfall displays, channel overlap/utilization analysis, interference detection, heatmap visualization, and environment baselining.
  • Client & Roaming Intelligence BSS transition tracking, roaming path graphing, sticky client detection, band steering analysis, and client identity profiling.
RustTauri 2.0SvelteKitTypeScriptSQLite

Also built

The evolution · four generations

Focused Operational Tools

Repetitive manual troubleshooting becomes structured, concurrent analysis.

  1. PA-DIAG Palo Alto firewall and VPN diagnostic engine: 60+ parallel diagnostic operations, anomaly correlation, TAC-ready evidence packages. Rust · Tokio · Tauri · SvelteKit · PAN-OS APIs · SSH
  2. GP-MEDIC GlobalProtect troubleshooting companion: authentication, portal, gateway, endpoint, certificate, and connectivity failures through one repeatable workflow. GlobalProtect APIs · Rust · Python · log parsing
  3. PanOS Evaluator Firewall-policy analysis: shadowing, redundancy, overlap, risk, and configuration hygiene across rules, objects, and services. PAN-OS XML · Rust · TypeScript · normalized object models
  4. Layers Structured Layer 1-7 troubleshooting organized around the OSI model instead of disconnected commands. Rust · Python · DNS · transport validation · TLS inspection
  5. Surveyor Environment inspection: endpoint, host, network, and infrastructure state discovered and normalized. Rust/Python agents · network discovery · structured telemetry
  6. Network Discovery Engine Discovery and source-of-truth population: devices, interfaces, addressing, topology, and capabilities with confidence scoring. Python · NetBox · Nornir · NAPALM · SSH
  7. Mapping Utilities MAPR, UUID-MAPR, Zone-MAPR: visual tools connecting identifiers, zones, objects, devices, and operational relationships. TypeScript · SvelteKit · SVG/Canvas · graph models
  8. Endpoint Reports Endpoint assessment: inventory, health, configuration, and security findings turned into shareable evidence. Rust · Tauri · SvelteKit · system APIs · export pipelines
  9. Troubleshooting Systems A wider collection of diagnostic, traffic, scanning, and support utilities automating narrow, repetitive workflows. Rust · Python · PowerShell · packet/log analysis

Vendor-Specific Operational Platforms

Single tools mature into full operational surfaces per vendor.

  1. VERTEX Local-first Palo Alto operations: discovery, diagnostics, policy analysis, lifecycle, hygiene, change planning, validation, evidence. Rust 2021 · Tokio · Tauri 2 · Svelte 5 · SQLite · PAN-OS XML · AES-256-GCM · Argon2
  2. PRISM Cisco operations and assurance: controller discovery, switch health, topology, compliance, direct-device access, remediation planning. Rust · Tauri 2 · Catalyst Center APIs · RESTCONF · NETCONF · NX-API
  3. AETHER Aruba automation and assurance across Central, AOS-CX, wireless, ClearPass, EdgeConnect, UXI, and fabric environments. Rust 2024 · Tauri 2 · gNMI · typed IPC · WebGPU topology
  4. LABYRINTH NetBox-centered reconciliation and assurance for telecom and fiber: intent versus reality, digital twins, safe automation, evidence. Rust · Axum · Python · Batfish · JetStream · GitOps

Cross-Vendor Control Planes

Vendor silos collapse into shared identity, normalized state, unified workflows.

  1. PA-CNTRL Early Palo Alto control plane: policy operations, diagnostics, traffic analysis, lifecycle, and Panorama automation behind one interface. Rust · Tauri · SvelteKit · PAN-OS APIs · SSH
  2. Cisco-CNTRL Cisco control plane: Catalyst Center, ISE, switching, compliance, inventory, interface health, operational automation. Rust · Tauri · Cisco controller APIs · RESTCONF · NETCONF
  3. Mist-CNTRL Juniper Mist surface: wireless inventory, site state, client visibility, configuration, API-driven automation. Mist APIs · TypeScript · SvelteKit · normalized models
  4. CNTRL-OMNI Cross-vendor aggregation exploring shared workflows and normalized resources across incompatible platforms. Rust · TypeScript · shared API contracts · RBAC
  5. CNTRL The consolidation: Panorama, ISE, Catalyst Center, Mist, and Infoblox behind shared identity with 70+ documented capabilities. Rust · Tauri · SvelteKit · Python · JWT · Argon2 · vendor APIs · Ansible

Governed Intelligent Platforms

Intelligence enters, but only inside deterministic architecture and human control.

  1. PANTHEON The flagship governed engineering platform: natural-language intent becomes typed plans, executed by agents and tools under policy, simulation, and evidence. Rust · Tokio · Tauri 2 · Svelte 5 · MCP · Tree-sitter · Monaco · OpenTelemetry
  2. AEON Private life and household operating system: authoritative records, shared groups, RBAC, tasks, documents, finance, bounded AI assistance. Svelte 5 · PWA · Rust · Axum · SQLx · passkeys · local inference
  3. SYN4PS3 Natural-language infrastructure operations: a centralized orchestration and governance plane separated from a local execution engine near the managed environment. Rust execution engine · typed APIs · tray/headless agents · policy controls
  4. PRISMATIK Multi-asset financial intelligence and quantitative research: equities, crypto, options, filings, simulation, paper trading, risk analysis. Rust · Tauri 2 · WebGPU · PostgreSQL · ClickHouse · Arrow · EDGAR data
  5. CALLISTO Privacy-first Rust browser: secure workspaces, profile isolation, vault, VPN routing, privacy enforcement, AI assistance. Rust · Tauri 2 · wgpu · Vello · WireGuard · signed modules
  6. MYTHOS AI Applied AI research and assurance program: model selection, evaluation, governance, benchmarking, adversarial testing, provenance. Python harnesses · Rust/TS references · MCP · benchmark suites · model cards
  7. GHOSTSHELL Secure developer workstation and terminal architecture: PTY and session management, encrypted vaults, sandboxed commands, SSH/VPN, hybrid TLS. Rust async · encrypted vaults · sandboxing · observability · post-quantum
  8. Shared Governance Architecture The common spine across every platform: durable missions, model-independent agents, typed tool contracts, approvals, reconciliation, verification, rollback. Rust · Tokio · MCP · OpenTelemetry · GitOps · policy engines
Contact

Let’s build
defensible infrastructure.

Open to senior network security, DevOps, and cleared roles, remote or in the San Diego area. The full résumé, references, and cover letter are available below.

MYTHOS/SYSTEMS © 2026 Aaron Stovall · Set in Fraunces & Inter · Built with SvelteKit