AWS WAF & reCAPTCHA v3 Security

Job ID: 40109490

Budget: €250 – €750 EUR

My main goal is enhancing security, and the focus is squarely on my API endpoints hosted in AWS. I need a specialist who can put a robust Web Application Firewall in front of those endpoints and weave Google reCAPTCHA v3 into the request flow so automated attacks and abusive traffic are stopped before they reach the application layer.

Here’s what I’m aiming for: configure AWS WAF with the appropriate managed rule sets, add custom rate-limit and IP reputation rules where they make sense, and make sure everything is logged to CloudWatch for easy monitoring. Once the WAF is in place, I want reCAPTCHA v3 integrated so legitimate users pass through seamlessly while bots get flagged.

If you prefer Infrastructure-as-Code, feel free to work in Terraform or CloudFormation. Just leave me with clean, well-commented templates and a short hand-over guide so I can keep things running after the project wraps.

Deliverables
• AWS WAF deployed and attached to the existing API Gateway or ALB
• Custom and managed rule sets tuned for my traffic profile
• reCAPTCHA v3 verification added to the API’s authentication or critical endpoints
• Logging and metrics wired into CloudWatch (or another AWS native service you recommend)
• A brief document outlining the configuration and how to adjust it in the future

I’m looking for someone who has done this before and can move quickly while keeping false positives low and security high.