HIPAA-Ready EC2 & S3 Optimization
Budget / SalaryHourly project
TypeFreelance project
LocationRemote
Posted1 hour ago
I’m overhauling our AWS footprint and need an experienced cloud engineer to take full ownership of our EC2 and S3 environment so it is production-grade, cost-efficient, and fully aligned with HIPAA requirements. The scope covers three intertwined streams of work: first-time setup and configuration, ongoing scaling and performance tuning, and a rock-solid security and monitoring layer.
For EC2, you will design the instance strategy, build Auto Scaling Groups, craft launch templates, and tune networking, storage, and AMIs so workloads can grow predictably without runaway costs. On S3, I want buckets structured for data segregation, lifecycle rules, intelligent tiering, versioning, server-side encryption (SSE-KMS), and cross-region replication where it makes sense.
The security mandate is non-negotiable. Every piece must map to HIPAA safeguards: IAM roles with least privilege, VPC subnet isolation, security groups and NACLs, GuardDuty, CloudTrail, Config, and end-to-end logging to a central, immutable store. I’ll also rely on your guidance to document the controls and produce audit-ready evidence.
Deliverables
• Architecture diagram highlighting EC2, S3, networking, and security flow
• Infrastructure-as-Code (Terraform or CloudFormation) with clear variables and README
• Hardened AMI build or pipeline scripts (Packer, EC2 Image Builder)
• Monitoring stack (CloudWatch dashboards, alarms, SNS notifications)
• Compliance report mapping implemented controls to HIPAA citations
• Knowledge-transfer session and step-by-step runbook
Acceptance criteria
All code deploys cleanly in my AWS account, passes spot checks with AWS Trusted Advisor and the HIPAA Security Checklist, and demonstrates sustained performance under a controlled load test.
If you’re comfortable working hands-on with EC2, S3, IAM, VPC, CloudWatch, GuardDuty, and Terraform/CloudFormation—all through a HIPAA lens—let’s get started.
For EC2, you will design the instance strategy, build Auto Scaling Groups, craft launch templates, and tune networking, storage, and AMIs so workloads can grow predictably without runaway costs. On S3, I want buckets structured for data segregation, lifecycle rules, intelligent tiering, versioning, server-side encryption (SSE-KMS), and cross-region replication where it makes sense.
The security mandate is non-negotiable. Every piece must map to HIPAA safeguards: IAM roles with least privilege, VPC subnet isolation, security groups and NACLs, GuardDuty, CloudTrail, Config, and end-to-end logging to a central, immutable store. I’ll also rely on your guidance to document the controls and produce audit-ready evidence.
Deliverables
• Architecture diagram highlighting EC2, S3, networking, and security flow
• Infrastructure-as-Code (Terraform or CloudFormation) with clear variables and README
• Hardened AMI build or pipeline scripts (Packer, EC2 Image Builder)
• Monitoring stack (CloudWatch dashboards, alarms, SNS notifications)
• Compliance report mapping implemented controls to HIPAA citations
• Knowledge-transfer session and step-by-step runbook
Acceptance criteria
All code deploys cleanly in my AWS account, passes spot checks with AWS Trusted Advisor and the HIPAA Security Checklist, and demonstrates sustained performance under a controlled load test.
If you’re comfortable working hands-on with EC2, S3, IAM, VPC, CloudWatch, GuardDuty, and Terraform/CloudFormation—all through a HIPAA lens—let’s get started.
Apply on Freelancer →
Project sourced from Freelancer.com. Applications happen directly on the original platform — we never collect your data.