AWS Secure Data Space Build

Job ID: 40505462

Budget: $250 – $750 USD

I want a production-ready data space on AWS where authorised users can log in, browse, and download documents while every byte remains encrypted and every action is auditable.
My architecture is fixed:

• Amazon S3 — primary object storage with AES-256-bit encryption at rest
• Amazon Cognito — user pools and federated identity for secure sign-in
• AWS Amplify — web interface so users can authenticate and view/download files over TLS 1.2+
• AWS CloudTrail + fine-grained IAM — continuous logging and audit trails

On top of that baseline I also need dynamic watermarks, DRM controls, and expiring access links to satisfy SOC 2 Type II, ISO 27001, and the NIST Cybersecurity Framework.

Most critical to success is hands-on expertise with S3, Cognito, Amplify, and CloudTrail; I’m only considering freelancers who have already delivered comparable AWS solutions. Please include links, screenshots, or live demos of past work that prove your experience—placeholder bids or generic résumés will be ignored.

Deliverables (acceptance criteria):
1. CloudFormation or CDK stack that deploys the full environment repeatably.
2. Amplify front-end connected to Cognito user pool, operational behind HTTPS.
3. Document controls implemented: watermark overlay, DRM/blocked download where required, expiring signed URLs.
4. CloudTrail logging every API call and user event, with retention policy applied.
5. Written configuration showing how the setup aligns with SOC 2 II, ISO 27001, and NIST controls.

Provide a realistic timeline and final price in your bid. Once complete I will test with sample files and user accounts; payment is released after the environment meets the criteria above and your demo confirms functionality.