Urgent Need: Cloud Security Enhancement Specialist

Job ID: 40224284

Budget: ₹1,500 – ₹12,500 INR

Cloud Security Specialist – Immediate Infrastructure Hardening (Short Term)

Project Overview

Duration: 3 to 5 days
Location: Remote
Start: Immediate

A healthcare technology platform requires a Cloud Security Specialist to implement quick security improvements identified in a recent penetration assessment.

This is a focused, short-term assignment aimed at reducing immediate attack surface exposure at the infrastructure layer.

Scope of Work

All listed tasks must be completed.

1. Server Version Disclosure Prevention

Remove server and framework version information from HTTP responses.

Responsibilities

Configure AWS Application Load Balancer to remove server headers
Update CloudFront response headers policy
Disable X Powered By headers in Next.js
Customize error responses to prevent version leakage
Validate using curl, browser developer tools, and security scanners

2. SSL/TLS Hardening

Strengthen TLS configuration to meet modern security standards.

Responsibilities

Update ALB to TLS 1.2 and 1.3 only
Disable weak protocols and insecure cipher suites
Implement security headers including HSTS, X Frame Options, X Content Type Options
Validate certificate chain and OCSP stapling
Achieve SSL Labs A+ rating

3. Open Port and Security Group Audit

Conduct infrastructure-level network exposure review.

Responsibilities

Perform port scans on staging and production
Audit AWS Security Groups
Close unnecessary or risky ports
Document required open ports with justification
Configure CloudWatch alerts for Security Group modifications

Technical Environment

AWS ap-south-1
ALB, CloudFront, EC2, RDS
Next.js / React
Tools available: nmap, OWASP ZAP, SSL Labs

Limited IAM access will be provided.

Required Experience

Minimum 3 years AWS infrastructure security
Strong TLS and cipher suite expertise
Experience with port scanning and vulnerability assessment tools
Web server security configuration knowledge

Deliverables

Hardened configuration implemented
Validation evidence
Security documentation summary