Secure FinTech Backend Architecture

Job ID: 40034919

Budget: $5,000 – $10,000 USD

I need an experienced backend engineer to stand up the very first version of our FinTech platform’s infrastructure. The sole goal of this MVP is to store and process sensitive data in a way that satisfies WISP and GLBA standards from day one, while also giving every customer a tamper-proof Unique ID managed through a centralized ID service.

Scope of work
• Design and deploy the foundational AWS + Firebase stack (VPC, subnets, IAM roles, KMS-backed encryption, Firestore/Realtime DB or Aurora Serverless, Cloud Functions/Lambda, CloudFront/API Gateway) so that Personal Identifiable Information and limited financial-transaction data are protected at rest and in transit.
• Implement the centralized ID management system that issues, rotates, and validates Unique IDs for each user and each data record.
• Wire basic CRUD endpoints (REST or GraphQL) for user onboarding, authentication, and data retrieval, making sure token scopes align with Least-Privilege principles.
• Produce concise WISP/GLBA compliance evidence—diagrams, configuration snapshots, and logging policies—sufficient for an external audit.

Acceptance criteria
– All PII and transaction fields are encrypted using AWS KMS–managed keys or Firebase’s CMEK equivalent.
– Unique IDs remain consistent across services and survive data migrations.
– Automated CI/CD scripts (CloudFormation or Terraform preferred) reproduce the environment in a single command.
– Unit tests and a short run-book prove that no endpoint leaks PII in error messages or logs.

I will provide the domain model, minimal user stories, and access to our AWS and Firebase projects; you return the infrastructure code, documented endpoints, and compliance package so we can hand the auditors something rock-solid.