Angelo F Signature

Angelo Frammartino

Information Security Analyst | Incident Response | Identity & Privileged Access | Security Automation

Information Security Analyst at The Timken Company, where I serve as the lead North American CrowdStrike incident response and remediation analyst. My work spans endpoint detection and response, identity and privileged access management, data loss prevention, and security support for M&A integrations.

Recent work includes auditing the enterprise administrative account population and removing 107 of 146 accounts as stale or unnecessary, and authoring a security automation development standard governing input validation, privileged-account scope control, and change control across the team’s PowerShell estate.

Outside of work, I continue building practical security tools, including The EntropyX Platform, my enterprise compression suite, identity governance platform and home network security application.

View My Work

About Me

Information Security Analyst with 4+ years of experience across incident response, vulnerability management, and enterprise security operations in global environments. At The Timken Company I lead North American CrowdStrike incident response and remediation, own the Varonis data security platform as primary analyst, and support InfoSec workstreams for mergers and acquisitions. Earlier, at Apple Growth Partners, I served as cybersecurity administrator for a firm with no dedicated security team and raised firm-wide security compliance from 50% to 85%.

My focus is increasingly on the governance side of security operations: reducing standing privileged access, and making the automation that administers identity safe to run. I recently audited the enterprise administrative account population and removed 107 of 146 accounts as stale or unnecessary, and authored a security automation development standard covering input validation, mandatory preview on destructive operations, privileged-account scope control, credential handling, and change control.

Day to day I work across CrowdStrike Falcon, Varonis, Microsoft Defender XDR, Intune, Active Directory and Entra ID, MOVEit Transfer, and PowerShell. Certified in ISC2 SSCP, CompTIA SecurityX (CASP+), CySA+, Security+, and PenTest+.

Security Operations

CrowdStrike Falcon, SIEM monitoring, threat detection, malware analysis

Vulnerability Management

Risk analysis, proactive assessments, patch management, security controls

Microsoft 365 Security

Defender XDR, Intune, Entra ID, Endpoint Manager, MDM

Privileged Access Governance

Admin account auditing, standing access reduction, CyberArk, Delinea Secret Server

Security Automation

PowerShell tooling, development standards, change control, audit logging

Incident Response

Alert response, security workflows, automated remediation, continuous improvement

Identity Management

Active Directory, Entra ID, access provisioning, least-privilege review

Data Security & DLP

Varonis, CrowdStrike DLP, MOVEit Transfer, sensitive data monitoring

Experience

Information Security AnalystCurrent

The Timken Company — North Canton, OH
02/2026 – Present

Lead North American CrowdStrike incident response and remediation analyst, giving the region a single accountable owner for endpoint detections so threats are contained before they spread laterally. Primary analyst for Varonis, monitoring and triaging alerts on sensitive data access to surface unauthorized and anomalous file activity.

Audited all 146 administrative accounts across the environment and removed 107 as stale or unnecessary, cutting standing privileged access by 73%. Maintain the MOVEit Transfer server and apply security patches on release. Support InfoSec workstreams for M&A integrations, bringing acquired environments up to enterprise security standards.

Fulfill security access requests spanning VPN, USB access, IAM in Active Directory, and service account creation, applying least-privilege review. Authored a security automation development standard governing script structure, input validation, privileged-account scope control, credential handling, and change control, and rebuilt the team’s PowerShell estate to conform.

Support Engineer

Eide Bailly LLP — Akron, OH
06/2024 – 02/2026

Served as the primary local IT and end-user computing representative for the Great Lakes region, encompassing 5 offices across Ohio, Illinois, and Virginia. Managed laptop deployment, provisioning, and decommissioning for new hires and terminations.

Ensured vulnerability remediation and patch management for regional laptops and network devices. Managed Active Directory objects for seamless onboarding, access control, and inventory accuracy. Utilized BeyondTrust Bomgar for remote support, and leveraged Delinea Secret Server and Connection Manager to secure privileged access and monitor remote sessions. Used ServiceNow to manage incidents and user requests.

IT Support Specialist

Apple Growth Partners — Akron, OH
01/2022 – 06/2024

Acted as cybersecurity administrator, monitoring Microsoft Defender SIEM, responding to alerts, performing malware remediation and analysis, conducting root cause analysis, and producing executive documentation. Raised firm-wide security compliance from 50% to 85%.

Managed KnowBe4 cybersecurity awareness and training programs. Used FreshService to respond to helpdesk tickets and worked within a small team to maintain day-to-day applications. Deployed, provisioned, updated, and maintained user laptops across the firm.

College of Business, Lab Assistant

The University of Akron — Akron, OH
08/2018 – 06/2021

Worked independently and collaboratively as part of a 7-member lab assistant team supporting five labs. Maintained up-to-date computer systems by implementing the latest security updates and best practices. Diagnosed and resolved PC issues, selecting and applying the most effective solutions.

Featured Projects

Security Posture Improvement - Apple Growth Partners

Improved organizational security posture from 50% to 85%. Implemented vulnerability remediation, patch management, and comprehensive security monitoring using Microsoft Defender XDR and KnowBe4.

Vulnerability Management Security Admin Defender XDR

Industrial Control Systems (ICS) Network

Designed and configured multi-subnet ICS environment with SCADA systems, DMZ, and corporate network using VLSM. Implemented firewall policies, static routing, and network segmentation for critical infrastructure protection.

SCADA VLSM Configuration Network Architecture ICS Security

Snort IDS Implementation & Rule Development

Installed and configured Snort on Kali Linux for intrusion detection. Created custom detection rules for phishing, unauthorized SMB access, port scanning, and malicious IP communication across multi-tier network architecture.

Snort Kali Linux IDS Rule Writing

Digital Forensics with Autopsy

Conducted forensic analysis on Kali Linux VM using Autopsy. Performed data source ingestion, configured hash lookup and encryption detection modules, and analyzed file systems to identify artifacts and deleted files.

Digital Forensics Autopsy Evidence Analysis

MITRE ATT&CK Threat Advisory

Developed comprehensive threat advisory documenting 12 MITRE ATT&CK tactics with techniques and mitigations. Covered initial access through impact stages including persistence, privilege escalation, and defense evasion strategies.

MITRE ATT&CK Threat Analysis Security Research

Network Tunneling & VPN Security Analysis

Analyzed tunneling protocols (GRE, PPTP, L2TP) and IPsec security mechanisms. Researched encapsulation techniques, authentication headers, and TLS improvements over SSL for secure network communications.

VPN IPsec Network Protocols