AWS & Plesk Server Security Hardening Expert – Full Lockdown, Billing Guidance & DocumentationManagement

Job ID: 39683297

Budget: $30 – $250 USD

AWS & Plesk Server Security Hardening Expert – Full Lockdown, Billing Guidance & Documentation

If you are not a true AWS + Plesk security professional, please skip this project.
I am looking for a world-class server hardening expert to make my Amazon AWS server and Plesk control panel impenetrable. I want top-notch security so no attacker, hacker, malware, or bot can compromise my system — ever.

This is not a “quick fix” job. I want **full end-to-end security, ongoing monitoring, and all controls to remain in my hands only. You must also guide me step-by-step on how to manage AWS billing, payments, usage, and monthly monitoring.

Scope of Work:

1. AWS Account & IAM Security

* Enable & enforce MFA for root
* Disable root API keys, create least-privilege IAM users
* Enable AWS CloudTrail, AWS Config, and billing alerts
* Restrict unused AWS regions

2. AWS Network & Firewall

* Configure strict **Security Groups** & NACL rules
* Allow only required ports (HTTP, HTTPS, custom Plesk port, SSH for my IP)
* Enable AWS WAF & Shield Standard
* Set up DDoS protection & bot filtering

3. Linux Server OS Hardening

* Update OS & enable automatic security updates
* Disable root password login, enforce SSH key authentication
* Install & configure Fail2Ban and CSF Firewall
* Disable unused services, close unused ports
* Enforce strong password policies

4. Plesk Security

* Change Plesk default admin port
* Enable ModSecurity with OWASP rules
* Enable Fail2Ban for SSH, Plesk login, and mail
* Install Let's Encrypt for Plesk login HTTPS
* Remove unused PHP versions & disable dangerous PHP functions
* Enable daily malware scanning (ImunifyAV or ClamAV)

5. Web & App Protection

* Force HTTPS for all hosted domains
* Disable directory listing & apply security headers
* Keep WordPress & all plugins updated (via WP-CLI if needed)

6. Backup & Recovery

* Daily full server backups to AWS S3 or secure remote storage
* Enable Plesk backup scheduler & test restores
* Maintain at least 7 days of rolling backups

7. Monitoring & Alerts

* Install real-time monitoring (Netdata, Monit, or Uptime Kuma)
* Email/SMS alerts for CPU, RAM, disk, downtime, failed services
* AWS CloudWatch alarms for resource usage spikes

8. Billing & Usage Guidance

* Show me AWS monthly payment dates & how to track
* Teach me to monitor GB/memory usage, costs, and billing
* Configure AWS Budget Alerts for spending limits

Deliverables:

1. Fully secured AWS + Plesk setup (following the above checklist)
2. Security report **before & after** implementation
3. Step-by-step AWS billing & usage guide for me
4. Backup & disaster recovery plan (tested & documented)
5. Ongoing monitoring system with alerts
6. Full documentation with commands, file paths, and configurations

Requirements:

* Proven AWS & Plesk server hardening experience
* Strong Linux server administration skills (Ubuntu/CentOS)
* Must provide references or examples of similar work
* Excellent communication & willingness to explain clearly

How to Apply:

Please include in your proposal:

1. A short explanation of your AWS + Plesk security experience
2. A list of tools & methods you will use
3. A recent example of a similar hardening project
4. Estimated time to complete the full checklist

Important: I will only consider professionals who understand full-stack AWS + Plesk security — no generic “install antivirus” shortcuts. I will verify every security measure you apply.