Angelo F Signature

Angelo Frammartino

Information Security Analyst | Incident Response | Identity & Privileged Access | Security Automation

Information Security Analyst at The Timken Company, where I lead endpoint incident response and remediation for the North American region. My work spans detection and response, identity and privileged access management, data loss prevention, and security support for M&A integrations.

Recent work includes a privileged access review that substantially reduced standing administrative access across the environment, and authoring a security automation development standard governing input validation, scope control, credential handling, and change control for administrative tooling.

Outside of work, I continue building practical security tools, including The EntropyX Platform, my enterprise compression suite, identity governance platform and home network security application.

View My Work

About Me

Information Security Analyst with 4+ years of experience across incident response, vulnerability management, and enterprise security operations in global environments. At The Timken Company I lead endpoint incident response and remediation for North America, serve as primary analyst for enterprise data security monitoring, and support InfoSec workstreams for mergers and acquisitions. Earlier, at Apple Growth Partners, I served as cybersecurity administrator for a firm with no dedicated security team and raised firm-wide security compliance from 50% to 85%.

My focus is increasingly on the governance side of security operations: reducing standing privileged access, and making the automation that administers identity safe to run. I recently led a privileged access review that substantially reduced the administrative account population, and authored a security automation development standard covering input validation, mandatory preview on destructive operations, scope control, credential handling, and change control.

My background spans endpoint detection and response, data security and DLP, SIEM operations, endpoint management, Active Directory and Entra ID, managed file transfer, and PowerShell automation. Certified in ISC2 SSCP, CompTIA SecurityX (CASP+), CySA+, Security+, and PenTest+.

Security Operations

EDR platforms, SIEM monitoring, threat detection, malware analysis

Vulnerability Management

Risk analysis, proactive assessments, patch management, security controls

Security Compliance and Audit Enforcement

Control evidence, access reviews, audit support, security standards authoring

Privileged Access Governance

Admin account auditing, standing access reduction, PAM platforms, least privilege

Security Automation

PowerShell tooling, development standards, change control, audit logging

Incident Response

Alert response, security workflows, automated remediation, continuous improvement

Identity Management

Active Directory, Entra ID, access provisioning, least-privilege review, CyberArk PAM

Data Security & DLP

Sensitive data monitoring, DLP policy design, managed file transfer, server upgrade and patch maintenance

Experience

Information Security AnalystCurrent

The Timken Company — North Canton, OH
02/2026 – Present

Lead endpoint incident response and remediation analyst for the North American region, providing a single accountable owner for endpoint detections so threats are contained before they spread laterally. Primary analyst for enterprise data security monitoring, triaging alerts on sensitive data access to surface unauthorized and anomalous file activity.

Led a review of the enterprise administrative account population, retiring stale and unnecessary accounts to substantially reduce standing privileged access. Own patch and vulnerability management for a managed file transfer platform. Support InfoSec workstreams for M&A integrations, bringing acquired environments up to enterprise security standards.

Fulfill security access requests spanning remote access, removable media, directory identity management, and service account creation, applying least-privilege review. Authored a security automation development standard governing script structure, input validation, scope control, credential handling, and change control.

Support Engineer

Eide Bailly LLP — Akron, OH
06/2024 – 02/2026

Served as the primary local IT and end-user computing representative for the Great Lakes region, encompassing 5 offices across Ohio, Illinois, and Virginia. Managed laptop deployment, provisioning, and decommissioning for new hires and terminations.

Ensured vulnerability remediation and patch management for regional laptops and network devices. Managed Active Directory objects for seamless onboarding, access control, and inventory accuracy. Utilized BeyondTrust Bomgar for remote support, and leveraged Delinea Secret Server and Connection Manager to secure privileged access and monitor remote sessions. Used ServiceNow to manage incidents and user requests.

IT Support Specialist

Apple Growth Partners — Akron, OH
01/2022 – 06/2024

Acted as cybersecurity administrator, monitoring Microsoft Defender SIEM, responding to alerts, performing malware remediation and analysis, conducting root cause analysis, and producing executive documentation. Raised firm-wide security compliance from 50% to 85%.

Managed KnowBe4 cybersecurity awareness and training programs. Used FreshService to respond to helpdesk tickets and worked within a small team to maintain day-to-day applications. Deployed, provisioned, updated, and maintained user laptops across the firm.

College of Business, Lab Assistant

The University of Akron — Akron, OH
08/2018 – 06/2021

Worked independently and collaboratively as part of a 7-member lab assistant team supporting five labs. Maintained up-to-date computer systems by implementing the latest security updates and best practices. Diagnosed and resolved PC issues, selecting and applying the most effective solutions.

Featured Projects

Security Posture Improvement - Apple Growth Partners

Improved organizational security posture from 50% to 85%. Implemented vulnerability remediation, patch management, and comprehensive security monitoring using Microsoft Defender XDR and KnowBe4.

Vulnerability Management Security Admin Defender XDR

Industrial Control Systems (ICS) Network

Designed and configured multi-subnet ICS environment with SCADA systems, DMZ, and corporate network using VLSM. Implemented firewall policies, static routing, and network segmentation for critical infrastructure protection.

SCADA VLSM Configuration Network Architecture ICS Security

Snort IDS Implementation & Rule Development

Installed and configured Snort on Kali Linux for intrusion detection. Created custom detection rules for phishing, unauthorized SMB access, port scanning, and malicious IP communication across multi-tier network architecture.

Snort Kali Linux IDS Rule Writing

Digital Forensics with Autopsy

Conducted forensic analysis on Kali Linux VM using Autopsy. Performed data source ingestion, configured hash lookup and encryption detection modules, and analyzed file systems to identify artifacts and deleted files.

Digital Forensics Autopsy Evidence Analysis

MITRE ATT&CK Threat Advisory

Developed comprehensive threat advisory documenting 12 MITRE ATT&CK tactics with techniques and mitigations. Covered initial access through impact stages including persistence, privilege escalation, and defense evasion strategies.

MITRE ATT&CK Threat Analysis Security Research

Network Tunneling & VPN Security Analysis

Analyzed tunneling protocols (GRE, PPTP, L2TP) and IPsec security mechanisms. Researched encapsulation techniques, authentication headers, and TLS improvements over SSL for secure network communications.

VPN IPsec Network Protocols