I will set up and secure your new AWS account with best practice baselines
GCP and AWS Cloud Engineer, Terraform Certified, 10 Years in Infra
About this Gig
Just opened an AWS account, or inherited one nobody has secured? I will put a solid security and cost baseline in place so you are not surprised by a breach or a bill.
Baseline setup includes:
- Root account lockdown, MFA, and IAM Identity Center or IAM users with least privilege
- CloudTrail, AWS Config, GuardDuty and Security Hub enabled
- Budgets and billing alerts
- Default VPC review, S3 Block Public Access, EBS encryption by default
- Optional: AWS Organizations and SCPs, even for a small setup without Control Tower
I also build small automations: Lambda functions for scheduled tasks, alerts, cross-account jobs and SSM automation.
What you get:
- A checklist of everything configured
- Terraform code (Standard and Premium)
- Recommendations for what to do next
Message me first with how many accounts you have and what is running in them.
Cloud provider:
Amazon Web Services
Expertise:
Installation
•
Migration
•
Debugging
•
Configuration
Cloud computing resource:
Route53
•
VPC
•
Security Groups
FAQ
Do you need root access to my AWS account?
No. I never ask for root credentials. A temporary IAM role or IAM Identity Center user with the permissions I list is enough, or I can deliver Terraform for you to apply yourself.
Does this work without Control Tower?
Yes. The baseline is designed for single accounts and small setups that do not use Control Tower.
