AWS account setup as per Security Compliance requirement for ISO27001

Job ID: 39973392

Budget: ₹12,500 – ₹37,500 INR

Project Description:

We are looking for an AWS security and compliance expert to configure our AWS environment in line with ISO 27001 controls and best practices.

The goal is to ensure our AWS setup meets information security, access control, and data protection requirements under ISO 27001 (Annex A controls).

Scope of Work

Governance & Access Management

Review and configure IAM policies, roles, and permissions following least privilege.

Implement MFA for all users and root account.

Enforce strong password policies.

Configure AWS Organizations, SCPs, and tagging standards.

Network & Infrastructure Security

Set up VPC architecture with public/private subnets.

Configure Security Groups, Network ACLs, and VPC Flow Logs.

Ensure all EC2, RDS, and Lambda instances use secure subnets and encryption in transit.

Configure Bastion host or VPN for restricted SSH/RDP access.

Data Protection

Enable encryption at rest using AWS KMS.

Ensure TLS 1.2+ for all data in transit (S3, API Gateway, RDS, Redis, etc.).

Configure S3 bucket policies, block public access, and logging.

Monitoring & Logging

Enable and configure:

CloudTrail (organization-wide)

CloudWatch Logs & Metrics

AWS Config

GuardDuty, Security Hub, and Inspector

Centralized log storage and retention policies.

Backup & Business Continuity

Set up automated backups, cross-region replication, and disaster recovery plan.

Document RTO/RPO values.

Deliverables

Fully configured AWS environment meeting ISO 27001 security controls.

Documentation and configuration summary.

Recommendations for ongoing compliance and monitoring.

Skills Required

AWS Certified Security – Specialty or equivalent experience.

Deep understanding of ISO 27001 Annex A controls.

Hands-on experience with AWS Config, GuardDuty, Security Hub, and KMS.

Familiarity with CIS Benchmarks or NIST 800-53 is a plus.

Timeline

Expected completion: 2 weeks