AWS & Azure · Infrastructure as Code · CI/CD · AI Infrastructure · SOC 2 & HIPAA

Hands-on cloud infrastructure,
built to run without me.

I'm a do-er, not a talker. I design, build, and automate well-architected cloud infrastructure — then document and hand it over so your team runs it without me. Deep, root-level engineering, not high-level diagrams and buzzwords.

Est. 2016
100% focused on Infrastructure as Code since 2017
3 + 4
AI-heavy startups (2 retail, 1 healthcare) and products delivered
7 yrs
ongoing contract running all AWS for 3 core enterprise apps
Tiny teams
efficient DevSecOps, alerts before issues arise

What I do

Hands-on engineering across the full lifecycle — from first architecture decision to compliant, automated, day-2 operations.

Cloud & Well-Architected Infrastructure

Cost-efficient, secure, auto-scaling environments where everything is automated. Deep, root-level knowledge of AWS and Azure services — built to real standards (AWS Well-Architected, Azure Cloud Adoption Framework), not keyword familiarity.

Infrastructure as Code

100% IaC since 2017. Terraform across clouds, plus CloudFormation on AWS and Bicep/ARM on Azure. Your whole environment as reviewable, repeatable, version-controlled code — GitHub and GitHub Actions are my preferred source and pipeline.

CI/CD & DevSecOps for Tiny Teams

Pipelines that let small teams ship safely and often. Automate everything, bake security in, and surface proactive alerts that warn before something breaks — not after.

Compliant Operations: SOC 2 & HIPAA

The process, execution, and documentation behind real SOC 2 — and the configuration, documentation, and execution behind HIPAA. Audit-ready operations, not checkbox theater.

Resilient Backups & DR That Just Works

Cost-efficient single-region, multi-AZ disaster recovery — AWS or Azure Availability Zones — that actually recovers, with offsite backups that defend against ransomware and account hijacking. No wasted spend on multi-region theater.

Cloud Migration

Workloads moved between clouds when the business needs it — including AWS ↔ Azure migrations driven by Terraform — without lock-in surprises or hidden operational debt.

AI Infrastructure — GPU & CPU, Cost-Aware

All three startups I've built for run heavy AI workloads — the first an early adopter whose infrastructure I designed and operated. Work runs on GPU or CPU depending on which delivers better price/performance at the time, keeping AI both fast and cost-efficient.

How it fits together

The shape of what I build: a cost-efficient, single-region multi-AZ cloud environment — the same pattern on AWS or Azure — deployed entirely through Infrastructure as Code and GitHub Actions.

Single-region, multi-AZ reference architecture — AWS or Azure Users reach a load balancer that distributes traffic to auto-scaling application tiers across two Availability Zones, backed by a multi-AZ managed database, with object-storage offsite backups and proactive monitoring. Each component maps to an AWS or Azure equivalent. Users / Internet Cloud Region — single region · VPC (AWS) / VNet (Azure) Load Balancer ALB (AWS) · App Gateway (Azure) Availability Zone A Auto Scaling — App Tier EC2/ECS (AWS) · VMSS/AKS (Azure) Managed DB — Primary RDS (AWS) · Azure SQL Availability Zone B Auto Scaling — App Tier EC2/ECS (AWS) · VMSS/AKS (Azure) Managed DB — Standby RDS (AWS) · Azure SQL sync Object Storage → Offsite Vault S3 (AWS) · Blob (Azure) — ransomware-safe Monitoring — Proactive Alerts CloudWatch (AWS) · Azure Monitor
Single-region, multi-AZ — the same pattern on AWS or Azure; cost-efficient resilience without multi-region theater.
GitHub Actions CI/CD pipeline A developer pushes to GitHub, which triggers GitHub Actions to build, test, and run Infrastructure as Code, then deploy to AWS or Azure. Developer + Claude GitHub source of truth GitHub Actions build test & scan IaC: Terraform · CloudFormation · Bicep AWS or Azure deployed push trigger deploy
Every change flows from GitHub through automated build, test, and IaC into your cloud — AWS or Azure.

Selected work

A few engagements that show the pattern: deep involvement from the start, dramatic cost wins, compliance done lean, and systems that run themselves. Client specifics kept confidential.

Retail-tech startup

From day one to massive scale

I built the cloud infrastructure from the very beginning and kept revising it toward excellence — re-architecting an API-based system into a highly decoupled, queue-based one. The result is almost fully automated and extremely cost-efficient: running compute drops to near zero when idle, then scales to thousands of containers within minutes, tracking load precisely as it rises and falls.

~$0 compute at idle → thousands of containers queue-based · decoupled

Architecture details confidential.

Healthcare startup · AI-driven

Compliant platform, stood up in 3 months

Designed, implemented, hardened, and optimized the cloud infrastructure in three months. The platform leans heavily on AI and is now reaching HIPAA and SOC 2 compliance — efficiently, professionally, and lean.

infra in 3 months HIPAA + SOC 2 AI-driven · lean

AI startup

Designed in a month, compliance fast-tracked

Infrastructure designed in a single month. Now driving SOC 2 Type I — targeted for completion in under 12 weeks — with SOC 2 Type II to follow, all while keeping operational overhead marginal. Like the others, the system relies heavily on AI.

infra in 1 month SOC 2 Type I < 12 wks → Type II

Enterprise — established business

Cloud built & run by a tiny team

I first brought the organization to the cloud with a lift-and-shift, then optimized it — cutting costs drastically while unlocking scalable expansion and mobile technologies. I kept minimizing operational overhead on the legacy estate while holding ~100% uptime, as cost-efficiently as the design allows. From there I designed, implemented, and operated their enterprise AWS cloud with a 1–2 person team covering 24/7 operations. Thanks to solid design, proactive alerting, and automation, it runs with almost no hand-holding.

drastic cost reduction ~100% uptime 1–2 person 24/7 ops

How I work

Understand first, build to prove, then engineer it for real. The aim is a solution your team owns — well-architected, automated, and compliant by design.

  1. 01

    Understand

    Ask questions, then more questions, until the real need and real constraints are clear.

  2. 02

    Prove

    Build a proof of concept to expose the pitfalls and the areas that actually matter.

  3. 03

    Validate

    Put it in front of your team, listen to feedback and suggestions, recommend, listen again.

  4. 04

    Build

    Turn the POC into a well-architected, fully automated solution — IaC, not tribal knowledge.

  5. 05

    Operationalize

    Define the compliant processes, document them, and execute — so it runs without me.

My goal is always to make myself replaceable. I automate the repetitive work and document everything so your team can run the system without me — that's where the real value is. And once I can be replaced, I'm ready for the next challenge.

How I'm different

A few opinions, earned the hard way, that shape every engagement.

A do-er, not a talker

I deliver deep insights and real improvements — hands on keyboard — not high-level diagrams and a tour of the right keywords.

Technology understood from the root

I spend less time on fancy diagrams that sketch possible-or-impossible solutions and miss critical details, and more time engineering well-architected systems that meet every objective efficiently.

Modern, decoupled design

API-based and queue-based processing — highly decoupled architectures that scale and fail gracefully.

Pragmatic disaster recovery

Multi-region DR is often asked for, but if an entire cloud region is down, the world has a bigger problem than the systems I work on. I focus spend on cost-efficient, high-performing, automated single-region multi-AZ DR — AWS or Azure Availability Zones — with offsite backups against ransomware.

AI-accelerated delivery

I use Claude to accelerate development and documentation and to automate more and more of the work — so you get more, faster.

Built to be handed over

No hogging repetitive work. Everything is automated and documented so your team can take it from here.

Certifications & continuous learning

32 certifications and counting — deep, hands-on experience, formally backed. Headline AWS credentials (both Professional certs plus Specialties), Azure at Expert level, and an active push into AI/ML. Verify links go to Credly.

Amazon Web Services

  • Solutions Architect – ProfessionalAWS · verify
  • DevOps Engineer – ProfessionalAWS · verify
  • Security – SpecialtyAWS · verify
  • Advanced Networking – SpecialtyAWS · verify
  • Associate trioSolutions Architect · Developer · SysOps Administrator

Microsoft Azure

  • Azure Solutions Architect ExpertMicrosoft · 2025
  • DevOps Engineer ExpertMicrosoft · 2025
  • Azure Administrator AssociateMicrosoft · 2025

AI & continuous learning

32 certifications and counting, spanning cloud, security, and delivery — with my current focus on AI/ML. I also work hands-on with AI every day, using Claude to accelerate design, development, and documentation and to automate more of the delivery. It's not just what I build on; it's how I build.

About

Glaser Consulting, LLC is the independent practice of Thomas Glaser, established in 2016 and focused 100% on Infrastructure as Code since 2017.

I've delivered well-architected infrastructure and CI/CD for three startups — two in retail and one in healthcare — and four products: cost-efficient, secure, auto-scaling, automated, and compliant, enabling highly efficient DevSecOps operations with very small teams. All three startups are heavy on AI; the first was an early adopter whose infrastructure I designed and operated — running efficiently across both GPU and CPU, shifting workloads to whichever offered the better pricing. For the past seven years I've also held an ongoing contract with a former employer, running all of their AWS needs across three core enterprise applications — highly efficient and fully automated.

I've also migrated workloads between clouds, including AWS to Azure using Terraform, when the business called for it.

My background spans strong hands-on engineering and software development through hands-on manager and hands-on director roles, with a path open to VP. I chose to start my own business instead. I'm very capable of building and leading teams — but my preference is to engineer, and that's where I do my best work.

Whatever the title, the aim is the same: solid, well-architected, automated infrastructure that's understood from the root, runs efficiently, recovers when it has to, and outlives the engagement.

There's more on my LinkedIn — full history, recommendations, and the certifications listed above.

What people say

A few words from people I've worked with.

"Thomas is a rare combination of accomplished team leader, experienced manager and gifted software and instrument designer. I have a great respect for his design talent and for his abilities as a project and software group manager… The communication with Thomas was insightful and productive and I enjoyed working with him."
Andrey GueorguievScientist · R&D
"Thomas is a great manager. He does not micromanage and instead gives enough freedom to do our jobs. However he also knows when to take charge when required and focus the work to achieve our goals."
Robert DeanCTO @ Homegrown

More recommendations on LinkedIn.

Let's talk about your infrastructure

Tell me what you're building or where things are stuck. I'll reply personally.

thomas@glaser-consulting.com

Prefer LinkedIn? Connect with me.