ABOUT THE ROLEWe are hiring a senior, hands-on engineer for a fixed 5 to 6 week, full-time, remote contract to deliver two pieces of infrastructure on AWS: a hardened security baseline across our account, and a sealed development environment where source code never leaves the cloud. This is a delivery role, not an advisory one. A week-by-week plan already exists. You will personally build and configure everything below, deliver it in Terraform, document it, and hand it over. WHAT YOU WILL BUILDWorkstream A: AWS security baseline- Enable and tune Cloud Trail, Guard Duty, AWS Config, Security Hub, Amazon Inspector and IAM Access Analyzer.- Enforce MFA and an IAM password policy; review IAM users and roles for least privilege.- Tighten security groups across the estate and move all administrative access to SSM Session Manager,
so no SSH or RDP is reachable from the internet.- Lock down S3 and database access; enable encryption at rest for EBS and RDS.- Set up centralised patching with SSM Patch Manager and backups with AWS Backup.- Configure security alerting with Cloud Watch alarms and SNS. Workstream B: Sealed Development Environment- Build an isolated dev VPC with default-deny egress using AWS Network Firewall.- Deploy Amazon Work Spaces virtual desktops with DLP controls: clipboard, local drive, USB and printing redirection disabled.- Configure Git Hub so repository access (web, git, API) is only possible from inside the dev workplace: SSO, IP allow list, hardened org policies. This part is well documented; prior Git Hub Enterprise admin experience is not required.- Set up AWS Code Artifact as a package pull-through cache and self-hosted Git Hub Actions runners inside the enclave.- Run a data-loss-prevention test matrix to prove code cannot leave; pilot with a small group, then roll out to all developers. Cross-cutting- Everything as infrastructure as code in Terraform.- Runbooks, an architecture diagram and admin documentation; a clean handover. REQUIRED (all fo