Corey Murillo

Director of IT | Infrastructure, Security & Compliance Leader

Ten years at a HIPAA-regulated healthcare-data company, the last seven as Director of IT. I built the security program from the ground up and own the audits that prove it.

99.9% Service Availability
64% Fewer Support Tickets
65% Faster Resolution
6 Years, Zero Audit Exceptions

Strategic IT Leadership

VENI VIDI VICI - These words, spoken by Julius Caesar after achieving victory at the Battle of Zela, embody my approach to IT challenges. Show up, assess the situation, and conquer through persistence and strategic thinking.

As Director of IT at Trojan Professional Services, a HIPAA-regulated healthcare-data company, I report to the CEO and run three departments - software development, technical support, and help desk - with a team of about 13 across the US, India, and the Philippines. I own the information security program and the annual HIPAA-HITECH, DirectTrust (formerly EHNAC), and SOC 2 audit cycle end to end, with NIST CSF grounding the controls.

My leadership philosophy centers on transforming IT from a cost center to a strategic business enabler. With over a decade of hands-on experience spanning cybersecurity, infrastructure, and IT operations, I've built a track record of delivering measurable results:

Clean Audit Record

I own the annual audit cycle end to end: a SOC 2 Type II examination plus six straight years of DirectTrust (formerly EHNAC) HIPAA-HITECH accreditation, including third-party and trading-partner audits.

Built Detection From Zero

I built the security information and event management (SIEM) and detection-engineering program from the ground up on Rapid7 InsightIDR, then led the response to the company's first confirmed intrusion - contained within hours with a full forensic timeline.

99.9% Availability

I raised service availability from ~96% to 99.9% across the on-premises data center and hybrid Azure/M365 estate through high-availability design and a structured maintenance program.

Measured, Faster Service Delivery

I instituted ticket, resolution-time, and closure measurement in 2019; a self-service stack cut annual support tickets 64% the following year, and mean time to resolve fell ~65% (86 to 30 days).

From network administration to security leadership, my journey has equipped me with a deep understanding of hybrid on-premises and Azure/M365 infrastructure, incident response, vulnerability management, and compliance audits. I believe in empowering teams, fostering clear communication, and ensuring that technology serves its ultimate purpose: enabling organizational success.

Projects & Portfolio

Hands-on delivery, with the numbers that came out of it

Public Repositories & Home Lab

Loading repositories...

Key Initiatives

Detection Engineering Program

I built the security information and event management (SIEM) platform from nothing on Rapid7 InsightIDR: fleet-wide Sysmon deployment, a dozen custom detections, and a triage discipline that cleared 85- and 56-alert backlogs to zero with no rule exceptions.

Rapid7 InsightIDR Sysmon Sophos

Secrets Management in Production

I deployed OpenBao (Vault-compatible) with Raft storage, cloud auto-unseal, OIDC auth, audit forwarding, and dynamic database credentials - eliminating shared, static DB passwords.

OpenBao Azure MariaDB

PHI Database Migration

I directed a SQL Server to MariaDB migration for a production protected-health-information (PHI) database: root-caused a data-corruption defect in the replication tooling, proved the fix in a lab, and validated 4.09M rows / 106 columns with zero corruption.

SQL Server MariaDB Docker

Endpoint & Identity Modernization

I rolled out Entra-backed Windows Local Administrator Password Solution (LAPS) across the workstation fleet, BitLocker with escrowed recovery keys on Intune, conditional-access cleanup, and rebuilt break-glass access for 11 admin accounts.

Intune Entra ID Windows LAPS

Secure Software Delivery

I manage the software development function through the software development lifecycle (SDLC) and led its transition from waterfall to Agile; shipped an AI-assisted sales-lead classifier to production with CI security scanning and mandatory review gates; rationalized the Azure DevOps pipelines and branch defaults.

Azure DevOps GitHub Actions Docker

Privileged Access Hardening

I ran an Active Directory security assessment (Purple Knight) and sequenced remediation across four phases: kerberoast closure, krbtgt rotation, RC4 retirement, and Domain Admins reduction.

Active Directory Purple Knight Kerberos

Help-Desk Platform Migration

I am leading the move from SysAid to Jira Service Management: a full rehearsal migration proven end to end, the ticket taxonomy rebuilt, and the cutover scheduled.

Jira Service Management SysAid ITIL

Technical Vision & Strategy

Modernization Without Disruption

I modernize infrastructure, identity, and secrets management - hybrid Azure/M365, Intune, OpenBao - in sequenced phases, so security and compliance improve without interrupting the business.

Security-First Culture

I build security awareness across the organization, engineer detection before it is needed, and treat HIPAA, NIST CSF, and SOC 2 as design inputs rather than annual paperwork.

Innovation & Automation

I automate the repetitive - self-service, CI/CD with security gates, scripted operations in PowerShell and Python, AI-assisted tooling where it reduces toil - so a small team can run like a larger one.

Business Alignment

I translate technical concepts into business value and present spend, risk, and audit posture to the CEO and executive team, so IT investments directly support organizational goals.

Areas of Expertise

Leadership & Strategy

  • IT Strategy & Governance
  • Budget Ownership & Vendor Management
  • Distributed Team Leadership (US, India, Philippines)
  • Executive Reporting to the CEO & Auditors
  • SDLC & Waterfall-to-Agile Transition
  • Security Awareness Programs

Cybersecurity

  • Security Monitoring & Detection Engineering (SIEM: Rapid7 InsightIDR, Sysmon)
  • Incident Response & Forensic Timelines
  • Vulnerability Management (Rapid7 InsightVM)
  • Active Directory & Privileged Access Hardening
  • Endpoint Protection (Sophos, Microsoft Defender)
  • HIPAA-HITECH, NIST CSF, SOC 2, DirectTrust

Cloud & Infrastructure

  • Azure (Entra ID, Key Vault, DevOps) & Microsoft 365
  • Hybrid On-Premises / Cloud Estate
  • Secrets Management (OpenBao, HashiCorp Vault)
  • Endpoint Management (Intune, Windows LAPS, BitLocker)
  • High-Availability Design & Business Continuity / Disaster Recovery
  • Windows Server, Active Directory, VMware, Docker

Operations & Development

  • CI/CD with Security Gates (Azure DevOps, GitHub Actions)
  • SDLC & Agile Methodologies
  • ITIL Service Management (Jira Service Management, SysAid)
  • Service Measurement (Ticket Volume, Mean Time to Resolve, Availability)
  • Automation & Scripting (Python, PowerShell)
  • SQL Server & MariaDB Administration and Migration

Certifications & Education

Continuous learning and professional development

Education

Master of Science

Virginia Tech

Information Technology

Expected Dec 2026

Bachelor of Science

Western Governors University

Cybersecurity and Information Assurance

2024

Certifications

CCSP

Certified Cloud Security Professional

ISC2

Expires: Jun 2027

GCIH

Certified Incident Handler

GIAC

Expires: Dec 2027

GSEC

Security Essentials

GIAC

Expires: Mar 2027

SSCP

Systems Security Certified Practitioner

ISC2

Expires: Apr 2029

PenTest+

Penetration Testing

CompTIA

Expires: Dec 2028

Project+

Project Management

CompTIA

Expires: Oct 2028

ITIL v4

Foundation

PeopleCert

Current

Network+

Network Administration

CompTIA

Expires: Dec 2028

CIOS

IT Operations Specialist

CompTIA

Expires: Dec 2028

A+

IT Operations

CompTIA

Expires: Dec 2028

ECES

Certified Encryption Specialist

EC-Council

Expired: Aug 2025

Get In Touch

Connect on LinkedIn, browse the code on GitHub, or verify credentials on Credly

Location

Long Beach, California

United States

Current Role

Director of IT

Trojan Professional Services