Compliance work that survives inspection
AlphaVerify is a compliance and AI governance practice built by someone who has implemented the controls he now helps other people pass, not just written about them. Hard problems, honest answers, and technical work that holds up whether the person checking it is an auditor, a regulator, or an incident at 2 a.m.
Principles
A control that isn't in the system isn't real. Policy documents describe intent. We build to the point where the system enforces it.
Standards reduce thrash, when used well. NIST, ISO, CMMC, and GDPR exist to answer "is this good enough" without relitigating it every quarter. We avoid the version of compliance that exists only for the auditor.
Direct work. You work with someone who has implemented this before, not a rotating bench of junior consultants learning on your engagement.
Fixed scope where it's honest. The Snapshot Assessment is fixed price because gap analysis is a bounded question. Remediation gets scoped once we know what we're fixing.
John Koontz
I run every AlphaVerify engagement myself, no account team, no bench of juniors. My government work centers on the DoD: technical partnerships, and a working understanding of how FAR- and DFARS-driven procurement and CMMC assessments actually play out, not just how the regulation reads. I've built and governed infrastructure in regulated and commercial environments, and earned the certifications, SOC 2 Type II, ISO 27001, FDA/IEC 62304, that only stick when your systems pass scrutiny, not your slide deck. I currently serve as fractional CTO for a venture-backed AI biotech company, so the AI governance and regulated-systems work on this site is what I do day to day, not just what I advise on.
25+ years of depth in identity, directory, network security, and infrastructure at scale, with a bias toward documented, transferable work that makes your next hire effective on day one instead of starting from a blank page.
Base
Champaign, IL · nationwide and remote by design
Registration
UEI: RUANZRL3RL83
Background
AI biotech company
2025-Present · Fractional CTO
Ongoing engagement covering AI systems, infrastructure at scale, and the regulatory work that comes with an AI-driven life sciences platform, through AlphaVerify's fractional CTO practice.
Ketryx Corporation
2022-2025 · Chief Operating Officer
Achieved SOC 2 Type II, ISO 27001, and FDA/IEC 62304 compliance at a Lightspeed-backed medical device software company. Built HIPAA-compliant, cross-continent infrastructure on AWS and Kubernetes while scaling the company from seed through Series B.
Wolfram Research
2011-2022 · CIO & VP Engineering
Led technical partnerships with the DoD, FBI, and CIA. Managed infrastructure for Wolfram Alpha, a top-2,000 global website, and served as technical lead on partnerships with Apple, Amazon, and Samsung.
Eastern Illinois University
2001-2011 · Associate Director, IT Architecture
Enterprise architect for 30,000 users. Managed data center and identity management systems, and implemented campus-wide security and compliance programs.
Earlier still: precision computational research at NASA and Argonne National Laboratory, where the habit of treating evidence as non-negotiable started.
Technical depth relevant to compliance work: identity and access management (Active Directory, LDAP, Kerberos, RADIUS, OAuth2, OIDC), network security (VPN, VLAN, firewall configuration, segmentation), infrastructure security (AWS, Windows and Linux server hardening, vulnerability management), and the frameworks themselves, NIST 800-171, NIST 800-53, SOC 2, ISO 27001, HIPAA, and FDA software requirements.
Work directly with the person doing the work
No account manager, no bench of juniors. Schedule a conversation about your compliance or technical leadership needs.