Corey Murillo
Director of IT | Infrastructure, Security & Compliance Leader
Ten years at a HIPAA-regulated healthcare-data company, the last seven as Director of IT. I built the security program from the ground up and own the audits that prove it.
Strategic IT Leadership
VENI VIDI VICI - These words, spoken by Julius Caesar after achieving victory at the Battle of Zela, embody my approach to IT challenges. Show up, assess the situation, and conquer through persistence and strategic thinking.
As Director of IT at Trojan Professional Services, a HIPAA-regulated healthcare-data company, I report to the CEO and run three departments - software development, technical support, and help desk - with a team of about 13 across the US, India, and the Philippines. I own the information security program and the annual HIPAA-HITECH, DirectTrust (formerly EHNAC), and SOC 2 audit cycle end to end, with NIST CSF grounding the controls.
My leadership philosophy centers on transforming IT from a cost center to a strategic business enabler. With over a decade of hands-on experience spanning cybersecurity, infrastructure, and IT operations, I've built a track record of delivering measurable results:
Clean Audit Record
I own the annual audit cycle end to end: a SOC 2 Type II examination plus six straight years of DirectTrust (formerly EHNAC) HIPAA-HITECH accreditation, including third-party and trading-partner audits.
Built Detection From Zero
I built the security information and event management (SIEM) and detection-engineering program from the ground up on Rapid7 InsightIDR, then led the response to the company's first confirmed intrusion - contained within hours with a full forensic timeline.
99.9% Availability
I raised service availability from ~96% to 99.9% across the on-premises data center and hybrid Azure/M365 estate through high-availability design and a structured maintenance program.
Measured, Faster Service Delivery
I instituted ticket, resolution-time, and closure measurement in 2019; a self-service stack cut annual support tickets 64% the following year, and mean time to resolve fell ~65% (86 to 30 days).
From network administration to security leadership, my journey has equipped me with a deep understanding of hybrid on-premises and Azure/M365 infrastructure, incident response, vulnerability management, and compliance audits. I believe in empowering teams, fostering clear communication, and ensuring that technology serves its ultimate purpose: enabling organizational success.
Projects & Portfolio
Hands-on delivery, with the numbers that came out of it
DirectTrust (EHNAC) HIPAA-HITECH Accreditation
2019 - PresentI have been the sole owner of the annual accreditation cycle since 2019: six consecutive years of DirectTrust (formerly EHNAC) HIPAA-HITECH audits with zero exceptions, including third-party and trading-partner audits, plus a SOC 2 Type II examination. I author and maintain the information security program, its policies, the business-continuity and disaster-recovery (BC/DR) plan, and the risk-assessment cycle, aligned to NIST CSF and the HIPAA Security Rule.
Public Repositories & Home Lab
Loading repositories...
Key Initiatives
Detection Engineering Program
I built the security information and event management (SIEM) platform from nothing on Rapid7 InsightIDR: fleet-wide Sysmon deployment, a dozen custom detections, and a triage discipline that cleared 85- and 56-alert backlogs to zero with no rule exceptions.
Secrets Management in Production
I deployed OpenBao (Vault-compatible) with Raft storage, cloud auto-unseal, OIDC auth, audit forwarding, and dynamic database credentials - eliminating shared, static DB passwords.
PHI Database Migration
I directed a SQL Server to MariaDB migration for a production protected-health-information (PHI) database: root-caused a data-corruption defect in the replication tooling, proved the fix in a lab, and validated 4.09M rows / 106 columns with zero corruption.
Endpoint & Identity Modernization
I rolled out Entra-backed Windows Local Administrator Password Solution (LAPS) across the workstation fleet, BitLocker with escrowed recovery keys on Intune, conditional-access cleanup, and rebuilt break-glass access for 11 admin accounts.
Secure Software Delivery
I manage the software development function through the software development lifecycle (SDLC) and led its transition from waterfall to Agile; shipped an AI-assisted sales-lead classifier to production with CI security scanning and mandatory review gates; rationalized the Azure DevOps pipelines and branch defaults.
Privileged Access Hardening
I ran an Active Directory security assessment (Purple Knight) and sequenced remediation across four phases: kerberoast closure, krbtgt rotation, RC4 retirement, and Domain Admins reduction.
Help-Desk Platform Migration
I am leading the move from SysAid to Jira Service Management: a full rehearsal migration proven end to end, the ticket taxonomy rebuilt, and the cutover scheduled.
Technical Vision & Strategy
Modernization Without Disruption
I modernize infrastructure, identity, and secrets management - hybrid Azure/M365, Intune, OpenBao - in sequenced phases, so security and compliance improve without interrupting the business.
Security-First Culture
I build security awareness across the organization, engineer detection before it is needed, and treat HIPAA, NIST CSF, and SOC 2 as design inputs rather than annual paperwork.
Innovation & Automation
I automate the repetitive - self-service, CI/CD with security gates, scripted operations in PowerShell and Python, AI-assisted tooling where it reduces toil - so a small team can run like a larger one.
Business Alignment
I translate technical concepts into business value and present spend, risk, and audit posture to the CEO and executive team, so IT investments directly support organizational goals.
Areas of Expertise
Leadership & Strategy
- IT Strategy & Governance
- Budget Ownership & Vendor Management
- Distributed Team Leadership (US, India, Philippines)
- Executive Reporting to the CEO & Auditors
- SDLC & Waterfall-to-Agile Transition
- Security Awareness Programs
Cybersecurity
- Security Monitoring & Detection Engineering (SIEM: Rapid7 InsightIDR, Sysmon)
- Incident Response & Forensic Timelines
- Vulnerability Management (Rapid7 InsightVM)
- Active Directory & Privileged Access Hardening
- Endpoint Protection (Sophos, Microsoft Defender)
- HIPAA-HITECH, NIST CSF, SOC 2, DirectTrust
Cloud & Infrastructure
- Azure (Entra ID, Key Vault, DevOps) & Microsoft 365
- Hybrid On-Premises / Cloud Estate
- Secrets Management (OpenBao, HashiCorp Vault)
- Endpoint Management (Intune, Windows LAPS, BitLocker)
- High-Availability Design & Business Continuity / Disaster Recovery
- Windows Server, Active Directory, VMware, Docker
Operations & Development
- CI/CD with Security Gates (Azure DevOps, GitHub Actions)
- SDLC & Agile Methodologies
- ITIL Service Management (Jira Service Management, SysAid)
- Service Measurement (Ticket Volume, Mean Time to Resolve, Availability)
- Automation & Scripting (Python, PowerShell)
- SQL Server & MariaDB Administration and Migration
Certifications & Education
Continuous learning and professional development
Education
Master of Science
Virginia Tech
Information Technology
Expected Dec 2026
Bachelor of Science
Western Governors University
Cybersecurity and Information Assurance
2024
Certifications
CCSP
Certified Cloud Security Professional
ISC2
Expires: Jun 2027
GCIH
Certified Incident Handler
GIAC
Expires: Dec 2027
GSEC
Security Essentials
GIAC
Expires: Mar 2027
SSCP
Systems Security Certified Practitioner
ISC2
Expires: Apr 2029
PenTest+
Penetration Testing
CompTIA
Expires: Dec 2028
Project+
Project Management
CompTIA
Expires: Oct 2028
ITIL v4
Foundation
PeopleCert
Current
Network+
Network Administration
CompTIA
Expires: Dec 2028
CIOS
IT Operations Specialist
CompTIA
Expires: Dec 2028
A+
IT Operations
CompTIA
Expires: Dec 2028
ECES
Certified Encryption Specialist
EC-Council
Expired: Aug 2025
Get In Touch
Connect on LinkedIn, browse the code on GitHub, or verify credentials on Credly
Location
Long Beach, California
United States
Current Role
Director of IT
Trojan Professional Services