AWS WorkSpaces & M365 Secure Setup
Budget: $250 – $750 AUD
AWS Workspaces Secure Environment Setup for Tax Compliance (ATO Requirements)
Project Overview
We are developing a cloud-based tax lodgment system for Australian individuals and small businesses.
To comply with ATO (Australian Taxation Office) security and data protection requirements, we must implement a highly controlled and auditable AWS Workspaces environment for our accounting team.
The goal is to isolate the accounting environment, restrict all external data transfer, and enforce strict network access and compliance monitoring.
Objectives
We are looking for an experienced AWS security engineer to help us design and implement the following setup:
1️⃣ AWS Workspaces Security & Data Leakage Prevention
All accountants will work exclusively within AWS Workspaces.
No data or files may leave the workspace under any circumstances.
Block file uploads to cloud storage (Google Drive, Dropbox, OneDrive, etc.).
Block email attachments to external domains.
Block IM apps (Teams, Slack, WhatsApp, WeChat, etc.) from sending files externally.
Restrict browser download/upload access.
Disable copy-paste between Workspace and local device.
Implement using a combination of:
AWS Workspaces policies / WorkDocs / DLP
IAM and SCP policies
VPC egress restrictions / Network Firewall / CloudWatch monitoring
2️⃣ Network Access Control
Workspaces should have a restricted outbound internet policy, allowing access only to:
✅ Our internal tax system (*.aupod.ai)
✅ Microsoft 365 services: Outlook and SharePoint
All other domains or IPs must be blocked.
3️⃣ SharePoint Access Restriction
SharePoint access must be allowed only from AWS Workspaces’ public IP addresses.
All external or personal devices must be denied access.
Configure Microsoft 365 Conditional Access Policies or IP-based restrictions accordingly.
4️⃣ Additional Security & Compliance (Optional but Recommended)
Enable CloudWatch / GuardDuty monitoring for login and access anomalies.
Enforce MFA (Multi-Factor Authentication) for all users.
Implement AWS Organizations + SCP to prevent accidental admin misconfiguration.
Generate audit and compliance reports suitable for ATO evidence submission. Deliverables
Fully configured AWS environment:
VPC, subnets, security groups, NAT/Firewall setup
AWS Workspaces creation and policies
DLP and network restriction configuration
Architecture diagram and configuration documentation
Testing report (verifying data transfer blocks and access restrictions)
Admin guide for maintenance and onboarding
Required Skills & Experience
Strong expertise in AWS Workspaces, VPC, IAM, Network Firewall
Experience configuring Microsoft 365 Conditional Access & SharePoint security
Hands-on experience with data loss prevention (DLP) and cloud compliance
Familiarity with ATO, SOC2, ISO 27001, or CPS 234 compliance frameworks is a plus
Ability to provide technical documentation in English
✅ Screening Questions
Have you previously configured AWS Workspaces with outbound domain or IP filtering?
Have you implemented Microsoft 365 Conditional Access for IP-based SharePoint restrictions?
What approach would you use to block file uploads and prevent data exfiltration from Workspaces?
Do you have experience with ATO, SOC2, or ISO27001 security compliance requirements?
Project Overview
We are developing a cloud-based tax lodgment system for Australian individuals and small businesses.
To comply with ATO (Australian Taxation Office) security and data protection requirements, we must implement a highly controlled and auditable AWS Workspaces environment for our accounting team.
The goal is to isolate the accounting environment, restrict all external data transfer, and enforce strict network access and compliance monitoring.
Objectives
We are looking for an experienced AWS security engineer to help us design and implement the following setup:
1️⃣ AWS Workspaces Security & Data Leakage Prevention
All accountants will work exclusively within AWS Workspaces.
No data or files may leave the workspace under any circumstances.
Block file uploads to cloud storage (Google Drive, Dropbox, OneDrive, etc.).
Block email attachments to external domains.
Block IM apps (Teams, Slack, WhatsApp, WeChat, etc.) from sending files externally.
Restrict browser download/upload access.
Disable copy-paste between Workspace and local device.
Implement using a combination of:
AWS Workspaces policies / WorkDocs / DLP
IAM and SCP policies
VPC egress restrictions / Network Firewall / CloudWatch monitoring
2️⃣ Network Access Control
Workspaces should have a restricted outbound internet policy, allowing access only to:
✅ Our internal tax system (*.aupod.ai)
✅ Microsoft 365 services: Outlook and SharePoint
All other domains or IPs must be blocked.
3️⃣ SharePoint Access Restriction
SharePoint access must be allowed only from AWS Workspaces’ public IP addresses.
All external or personal devices must be denied access.
Configure Microsoft 365 Conditional Access Policies or IP-based restrictions accordingly.
4️⃣ Additional Security & Compliance (Optional but Recommended)
Enable CloudWatch / GuardDuty monitoring for login and access anomalies.
Enforce MFA (Multi-Factor Authentication) for all users.
Implement AWS Organizations + SCP to prevent accidental admin misconfiguration.
Generate audit and compliance reports suitable for ATO evidence submission. Deliverables
Fully configured AWS environment:
VPC, subnets, security groups, NAT/Firewall setup
AWS Workspaces creation and policies
DLP and network restriction configuration
Architecture diagram and configuration documentation
Testing report (verifying data transfer blocks and access restrictions)
Admin guide for maintenance and onboarding
Required Skills & Experience
Strong expertise in AWS Workspaces, VPC, IAM, Network Firewall
Experience configuring Microsoft 365 Conditional Access & SharePoint security
Hands-on experience with data loss prevention (DLP) and cloud compliance
Familiarity with ATO, SOC2, ISO 27001, or CPS 234 compliance frameworks is a plus
Ability to provide technical documentation in English
✅ Screening Questions
Have you previously configured AWS Workspaces with outbound domain or IP filtering?
Have you implemented Microsoft 365 Conditional Access for IP-based SharePoint restrictions?
What approach would you use to block file uploads and prevent data exfiltration from Workspaces?
Do you have experience with ATO, SOC2, or ISO27001 security compliance requirements?