AWS Solutions Architect · San Antonio, TX

Michael Groff

Building serverless, scalable, cost-optimized platforms on AWS for SMB to enterprise; serverless-first, IaC everything, security by default.

Currently Sr. Solutions Architect @ AllCloud·12+ yrs cloud & hybrid infrastructure

Michael Groff
Happy at AllCloud; interesting conversations welcome.

About Me

I'm an AWS Sr. Solutions Architect at AllCloud, helping customers land on AWS the right way; serverless-first, IaC everything, security by default.

My background is ops (Rackspace Windows admin AWS Cloud Support Engineer), which shapes how I think about what gets deployed: it has to run at 2 a.m. on a Sunday without anyone waking up.

Off the clock

  • Native Texan from Bandera, TX
  • Married to a Texas public school teacher
  • Father of two daughters
  • Fur-father of three; two Huskies and one standard-issue cat
  • Based in San Antonio, TX
  • Avid tech enthusiast

Top 5 CliftonStrengths

Signature Themes PDF
#1Input

A need to collect and archive; information, ideas, artifacts, even relationships.

#2Achiever

Work hard with great stamina; immense satisfaction from being busy and productive.

#3Adaptability

Prefer to go with the flow; take things as they come and discover the future one day at a time.

#4Learner

Continuous desire to learn and improve; the process excites more than the outcome.

#5Positivity

Contagious enthusiasm; naturally upbeat, energizes others.

Gallup's CliftonStrengths assessment has been a good lens for how I collaborate and pick problems worth solving.

Skills & Stack

Things I use regularly enough to have opinions about. Recruiters can `⌘F` freely.

AWS

Primary cloud. Daily driver.

LambdaAPI GatewayS3CloudFrontDynamoDBEventBridgeSQS / SNSStep FunctionsCloudWatchCost ExplorerTrusted AdvisorIAMRoute 53ACMWAFVPCEC2ECS / Fargate

Infrastructure as Code

Everything deployable via pull request.

AWS CDK (TypeScript)SSTPulumiTerraformCloudFormation

Languages

Write, review, and refactor comfortably.

TypeScriptPythonBashPowerShell

Patterns & Practices

How I like to build.

Serverless-firstEvent-drivenAPI designStreamingMicroservicesBlue/green deploysCI/CD automationGitOpsWell-Architected FrameworkDisaster RecoveryCost optimization

Specializations

Industries and focus areas I've spent real time in.

On Prem -> Cloud migrationsCloud-> Cloud migrationsPlatform / app modernizationGreenfield cloud deploymentsHybrid: AWS, Azure, on-premDoD / Federal (IL4, FedRAMP)Generative AI integrationSecurity posture reviews

CI/CD & GitOps

Pipelines that ship; declarative delivery into Kubernetes.

GitHub ActionsGitLab CICircleCIArgoCDFluxCDHelmKustomize

Monitoring & Observability

Knowing what production is doing right now.

CloudWatchDatadogNew RelicPrometheusGrafana

Configuration Management

Server-side state, agent-driven.

AnsibleChefPuppet

Platforms & Tools

OS, virtualization, and adjacent tools I reach for often.

LinuxWindows ServerVMwareHyper-VKVMDockerKubernetesGit / GitHubCloudFlare

Depth varies; some are daily tools, others are things I've shipped to production and can speak to with real opinions. Happy to go deep on any of them.

Experience

AllCloud logo
Remote, based in San Antonio, TX
allcloud.io
May 2024Present
  • Architected and delivered comprehensive AWS cloud solutions tailored to meet customer-specific requirements, ensuring scalability, reliability, and cost-efficiency.
  • Integrated AI and machine learning solutions into customer workflows, enabling predictive analytics, automation, and intelligent decision-making to optimize operations.
  • Implemented serverless architectures using AWS services such as Lambda, API Gateway, S3, CloudFront, WAF and DynamoDB to deliver highly scalable and cost-efficient solutions with minimal infrastructure overhead.
  • Adopted modern cloud-native design principles, leveraging event-driven architectures, microservices, and containerization to ensure agility, maintainability, and rapid deployment cycles.
  • Led technical workshops and strategic IT discussions, advising SMB to enterprise customers on cloud adoption, modernization strategies, and best practices for leveraging AWS services.
  • Designed and implemented innovative cloud migration strategies, employing blue/green deployments and CI/CD pipelines to ensure seamless transitions with minimal downtime.
  • Collaborated with cross-functional teams to develop cloud architectures aligned with industry standards and compliance requirements, including advanced security and networking configurations.
  • Developed reusable infrastructure templates and patterns using Infrastructure as Code (IaC) tools like AWS CloudFormation and Terraform to accelerate deployment and enhance consistency.
  • Educated and mentored customers on AWS best practices, fostering cloud-native skill development and empowering them to maximize ROI from cloud investments.
  • Championed the use of generative AI tools and technologies to streamline operations and introduce cutting-edge capabilities, resulting in measurable improvements in efficiency and innovation.
  • Provided pre-sales support and technical guidance, contributing to successful deal closures and fostering long-term customer relationships through trusted advisory services.
  • Monitored and optimized cloud environments, leveraging AWS services like CloudWatch, Trusted Advisor, and Cost Explorer as well as many third party cost platforms to ensure optimal performance and cost-effectiveness.

Visit my blog at michaelgroff.info for technology write-ups and tutorials.

Letters of recommendation and contact information for all previous employers available upon request.

Praise

From people I've worked with

Michael is one of those rare AWS architects who can both draw the diagram and ship the CDK behind it. He made our cloud migration feel like a solved problem instead of a spreadsheet.

JP
Jane Placeholder
Director of Engineering · Former colleague · AllCloud

Calm under fire, writes docs people actually read, and is genuinely invested in the customer's success beyond the statement of work. Easy recommendation.

JP
John Placeholder
Principal Solutions Architect · Client · Innovative Solutions engagement

More recommendations on my LinkedIn profile.

Education

Texas State University campus, aerial view
Texas State University · San Marcos

Bachelor of Arts

School of Journalism & Mass Communication

A Journalism degree turned out to be training for writing design docs that people actually read.

Dean's List

Recognition across multiple semesters.

Intramural sports

Football and softball through school.

Bobcat Build

Student community service; Student Volunteer Connection.

The University Star

Student journalist for the university newspaper.

SAN MARCOS, TX·Eat 'Em Up Cats

Certifications

Full history · filter by vendor

Spans Dell/VMware partner enablement in 2017 through current AWS proctored exams. Click any dot or chip to verify on Credly.

About this site

WordPress → Next.js on AWS

The previous version of this site was a 2015-era WordPress install on The7 theme. This rewrite is its opposite: no server, no plugins, no database. Infrastructure is code. Deploys are a git push.

👤VisitorCloudFlareDNS · no proxycv.michaelgroff.infoCloudFrontedge CDN · OACredirect-to-httpsS3 (private)static exportcv-michaelgroff-devACM CertificateDNS-validated · us-east-1GitHub Actions · OIDC · CDKbuild · cdk deploy · s3 sync · invalidateHTTPSCNAMESigV4TLSsyncinvalidate
AspectWordPress (old)Next.js + AWS (new)
Monthly costBlueHost unlimited plan (shared across ~30 sites)Pennies per month (this site alone; actual numbers pending a few weeks of traffic)
First-load time3 to 4 s< 1 s
Security postureTheme + plugin patch treadmillZero server; signed OAC; managed TLS
Update workflowFTP or wp-admin clickopsgit push; Actions handles the rest
Infra definitionNone (clickops)AWS CDK in TypeScript

Design trade-offs

  • CloudFlare for DNS instead of Route 53; keeps this project single-account and lets me skip cross-account delegation. Trade-off: ACM validation needs a manual CNAME.
  • No WAF; saves ~$5/mo and a portfolio site doesn't warrant managed-rules cost.
  • OAC, not OAI; AWS's 2023+ recommended pattern for signed S3-origin access.
  • Static export, not SSR; zero servers and no per-request logic. Fits a resume, not a SaaS.