AWS Security / DevSecOps Contractor Needed This Week — Secrets Manager, IAM, EC2 Hardening

We are looking for an AWS Security / DevSecOps contractor for a short, urgent security hardening sprint. We need someone who can start immediately and complete the core setup by Friday.

Context:

We have an AWS server setup used for internal scripts, API-based workflows, and credential-based integrations. We want to make the environment more secure before giving broader access to team members or contractors.

Main goals:

Move API keys and sensitive credentials into AWS Secrets Manager

Remove secrets from code, config files, and .env files where possible

Set up least-privilege IAM roles and access levels

Create clear separation between admin, developer, read-only, and script/operator access

Restrict who can run specific scripts or workflows

Review EC2 access, SSH access, security groups, and open ports

Preferably move server access toward AWS Systems Manager Session Manager instead of open SSH

Enable or review CloudTrail, GuardDuty, CloudWatch logging, and basic security alerts

Review GitHub/deployment access if relevant

Create a short written runbook explaining who has access to what, where secrets are stored, and how scripts should be run safely

This is not meant to be a full penetration test or formal compliance audit. We need practical AWS hardening for a startup environment, with a focus on access control, secrets management, auditability, and reducing the chance of mistakes.

Requirements:

Strong AWS IAM/security experience

Experience with AWS Secrets Manager, EC2, CloudTrail, GuardDuty, CloudWatch, and Systems Manager

Comfortable working quickly and documenting changes clearly

Able to explain the access model in plain English

Available to start today or tomorrow

Able to complete the core setup by Friday

Please include in your response:

Relevant AWS security experience

Examples of similar hardening projects

Whether you can start immediately

Your hourly rate or fixed project estimate

How you would structure access for humans versus scripts/services

We are looking for someone practical, careful, and fast. Security matters here, but we need a focused sprint rather than a long enterprise audit.

Back to blog