Secure AWS Financial Supervision PoC

Job ID: 40022611

Budget: €18 – €36 EUR

This proof-of-concept will demonstrate a regulator-grade, fully secured VPC that hosts a central bank and multiple financial-institution tenants while automating supervision and compliance checks through native AWS services.

Scope
The environment must be carved into logically separate public and private subnets for every participant. The central bank sits in its own network segment and is able to observe, query, and enforce policy across all other institutions without exposing sensitive resources publicly.

Key services
• AWS Lambda for event-driven oversight logic and scheduled compliance sweeps
• AWS RDS for the authoritative supervisory data store
• AWS S3 as the immutable audit and reporting repository

Security & compliance
Networking, IAM, logging, encryption, and traffic inspection need to align with Government/Financial Institution Standards. That includes end-to-end TLS, KMS-managed encryption, fine-grained IAM policies, VPC flow-logs streaming to CloudWatch/S3, and easily auditable change control.

Deliverables
• Terraform / CloudFormation or CDK templates that build the VPC, subnets, route tables, NAT gateways, and security groups
• Deployment scripts and Lambda code that trigger compliance checks and write results to RDS and S3
• A concise run-book describing how the central bank dashboard calls the Lambdas, reviews reports, and updates policies
• Architecture diagram (PDF or draw.io) showing all components, trust boundaries, and data flows
• Final walkthrough session or recorded demo proving that an institution’s non-compliant event is detected and logged within the same VPC

Acceptance
The stack must deploy in a clean AWS account, pass a CIS benchmark scan at Level 1 without changes, and correctly store a sample regulatory breach in the audit bucket, viewable only by the central bank subnet.

All detailed functional requirements, sample data, and regulatory rules will be provided after kickoff.