
Closed
Posted
Paid on delivery
I need a specialist who can harden my Amazon S3 estate from end to end. The first phase is a thorough security assessment of every bucket: penetration testing to probe for exploitable paths, vulnerability scanning to catch mis-configurations or outdated settings, and a detailed access-control review that maps who can do what, and from where. When the testing phase is complete, I also want help turning the findings into action. That means building or updating the deployment workflows, bucket policies, IAM roles, lifecycle rules, and any supporting code so that fixes move cleanly from development into production. Because the work spans discovery and implementation, you will deliver: • A concise test plan outlining the tools and techniques you’ll use for the penetration tests, vulnerability scans, and access-control review • A written report summarising all findings, risk ratings, and reproduction steps • A remediation roadmap with clearly prioritised tasks • Updated CloudFormation/Terraform or AWS CLI scripts (whichever fits best) that implement the agreed changes, ready for deployment • A final verification run to confirm no critical or high-severity issues remain Acceptance criteria: all critical and high-risk issues are resolved or formally accepted, and bucket permissions adhere to least-privilege principles. If you are comfortable working hands-on with AWS security tooling and can move quickly from assessment into secure deployment, let’s make this happen.
Project ID: 40648749
26 proposals
Remote project
Active 5 hours ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
26 freelancers are bidding on average $93 SGD for this job

Hello, I have 10 years of experience in AWS security and cloud infrastructure. I am confident I can meet your needs for AWS S3 security testing and deployment. I will perform a thorough assessment of every S3 bucket using penetration testing and vulnerability scanning. I will provide a detailed access-control review with all findings and a remediation roadmap. I have expertise in creating and updating IAM roles, bucket policies, and deployment workflows. I will ensure all critical risks are resolved, adhering to least-privilege principles. Let's ensure your AWS S3 environment is secure from end to end. Regards, VishnuLal NB*
$100 SGD in 1 day
6.6
6.6

Hi there, I have over 10 years work experience with Linux and AWS (Certified x 2) and I think I can definitely help you out with this. Ping me! Cheers
$80 SGD in 1 day
5.7
5.7

Hi, I’m an experienced Cyber Security & Digital Forensics professional with strong hands-on expertise in AWS security, IAM, S3 security reviews, vulnerability assessment, penetration testing, and cloud hardening. I can perform a complete S3 security assessment covering bucket misconfigurations, public exposure, ACLs, bucket policies, IAM permissions, encryption, logging, lifecycle controls, access paths, and privilege escalation risks. I’ll document findings with risk ratings, evidence, and reproduction steps, followed by a prioritized remediation plan. I can also implement the fixes using Terraform/CloudFormation or AWS CLI, update IAM roles and bucket policies, improve deployment workflows, and perform a final verification/retest to confirm that critical and high-risk issues are resolved and least-privilege access is enforced. Deliverables:Test Plan - Security Assessment Report- Remediation Roadmap-Infrastructure-as-Code/CLI Changes -Final Verification Report. I can start immediately and work efficiently from assessment through secure production deployment. Regards, Kajal
$1,200 SGD in 7 days
5.3
5.3

We at Offensium Vault Private Limited (ISO 27001:2022 & ISO 9001:2015) can perform a comprehensive AWS S3 security assessment and hardening focused on access control, data exposure, and configuration risks. Scope & Methodology • Assess S3 buckets for public exposure, excessive permissions, insecure policies, and data-access risks. • Review IAM roles, bucket policies, ACLs, trust relationships, encryption, logging, versioning, lifecycle rules, and cross-account access. • Validate exploitable weaknesses through controlled, non-disruptive testing. • Review AWS services and deployment workflows affecting S3 security. • Tools: AWS CLI, CloudTrail, IAM Access Analyzer, Prowler, Nmap, and custom scripts. Key Security Areas Public bucket exposure, cross-account access, overly permissive IAM, credential misuse, insecure bucket policies, encryption gaps, logging deficiencies, data leakage, and configuration drift. Deliverables • Security assessment plan • Detailed report with severity ratings, evidence, PoCs, reproduction steps, and remediation guidance • Prioritized remediation roadmap • Updated AWS CLI / CloudFormation / Terraform configurations where required • Least-privilege IAM and bucket policy recommendations • Final retest confirming closure of Critical and High findings Our approach focuses on manual validation and actionable security improvements, not scanner-only results. Ready to begin once AWS access, scope, and Rules of Engagement are confirmed.
$50 SGD in 7 days
3.6
3.6

Being a Full Stack Developer with a specialization in Web Applications and Custom Software Development, I have had extensive experience working with Amazon Web Services (AWS), making me the perfect fit for this project. My expertise in Laravel, React.js, Node.js and AWS will allow me to deliver secure, scalable, high-performance solutions within your stipulated time frame. This project appears to be ideal for my skillset as it combines both security assessment and implementation - an area I've thrived in for years. My focus is on delivering secure, scalable, high-performance applications with clean architecture and long-term maintainability. I understand the importance of an end-to-end process in fortifying your S3 estate and I assure you of dedication throughout the stages:feasibility study, vulnerability scanning to secure deployment. As part of my service to your project, I will provide a concise test plan outlining my approach with penetration tests, vulnerability scans and access-control review that can help us get started on fixing identified security gaps. From there, I will deliver a comprehensive report of my findings along with a remediation roadmap that prioritizes tasks to address vulnerabilities. I am well versed in CloudFormation/Terraform scripts essential for implementing the agreed-upon changes after verification so that!
$45 SGD in 7 days
2.2
2.2

I will start by running a comprehensive audit of your IAM policies and bucket access logs to identify any over-privileged entities or public exposure risks. I prefer using Terraform to manage these configurations, as it allows us to version control your bucket policies and lifecycle rules, ensuring that your security posture is reproducible and auditable. For the penetration testing and vulnerability scanning, I will use a combination of automated AWS native tools and manual verification to simulate real-world attack vectors. Once we have the baseline, I will map your access controls to the principle of least privilege. My approach focuses on moving from discovery to remediation by refactoring your existing infrastructure code, ensuring that the hardening process does not break your current production workflows. I have extensive experience managing AWS environments using Terraform and CI/CD pipelines, focusing on securing S3 and IAM roles. My background in DevOps ensures that the security fixes I implement are maintainable and integrated directly into your deployment lifecycle. We can start by scheduling a brief call to discuss your current account architecture and the scope of the buckets you need secured.
$34.50 SGD in 4 days
1.6
1.6

I’ll assess each S3 bucket for public exposure, weak policies, ACL and IAM issues, encryption and logging gaps, lifecycle risks, and exploitable access paths. The review will combine AWS-native evidence with controlled validation of findings, documented reproduction steps, and risk-based prioritization. I’ll translate approved remediations into version-controlled Terraform, CloudFormation, or AWS CLI changes, covering bucket policies, IAM roles, encryption, public-access controls, logging, and deployment safeguards. A final verification will confirm the agreed security posture and record any formally accepted residual risks. Please confirm: is infrastructure currently managed through Terraform, CloudFormation, or another deployment process; and can the assessment cover all AWS accounts and regions that contain S3 buckets?
$30 SGD in 3 days
0.0
0.0

Public read access on versioned buckets can expose historic data even if current objects are locked. I'll start by enumerating all bucket ACLs and versioning settings with AWS CLI, then run a focused pen test on any public endpoints. Remediation scripts will be written in Terraform so the fixes can be applied uniformly across environments. A common pitfall is relying on bucket policies alone while leaving IAM user permissions overly broad, which can reintroduce risk after deployment. I'll set up an automated CI/CD step that runs the same scans after each Terraform apply, catching drift before it reaches production. Ready to start immediately and get the bucket estate hardened.
$50 SGD in 4 days
0.0
0.0

IF YOU'RE NOT HAPPY, YOU DON'T PAY. I recently completed a similar project where I improved the security of an S3 environment, resulting in a 30% reduction in vulnerabilities. I understand your need for a thorough security assessment followed by actionable remediation. I will conduct penetration testing, vulnerability scans, and access-control reviews to identify misconfigurations, ensuring a clean and secure setup. My experience with AWS will help streamline the transition from assessment to secure deployment, enhancing your S3 estate's overall integrity. I focus on good planning, clean and maintainable code, clear communication, on time delivery, and reliable long term solutions. I am confident in my ability to meet your requirements effectively. If this aligns with your project, feel free to reach out to discuss scope and pricing. WORST CASE SCENARIO YOU WALK AWAY WITH A FREE CONSULTATION. Regards ridwaan6254
$36 SGD in 7 days
0.0
0.0

Hi, I can help secure your **Amazon S3 environment from assessment through remediation and final verification**. I have 5+ years of software engineering experience working with secure backend systems, AWS/cloud environments, access control, APIs, Docker, and CI/CD. My approach will cover: * S3 bucket security and misconfiguration assessment * IAM roles, policies and least-privilege review * Public/cross-account access analysis * Encryption, logging, versioning and lifecycle rules * Identification and prioritisation of security risks * Terraform/CloudFormation or AWS CLI remediation * Deployment workflow improvements * Final verification of all critical/high-risk findings I’ll provide the requested **test plan, security findings report with risk ratings, remediation roadmap, deployment-ready configuration/scripts, and final verification results**. I’m comfortable working hands-on from discovery through implementation rather than only reporting issues. I can start immediately. Once I know the number of AWS accounts/buckets and your current IaC setup, I can confirm the timeline.
$65 SGD in 3 days
1.3
1.3

Hi there, I've reviewed your project requirements and I'm confident I can deliver exactly what you need. I'm a Senior Full Stack Developer with strong hands-on experience in React.js/React Native and modern web development practices. I focus on writing clean, scalable code and have a track record of delivering projects on time without compromising quality. On Freelancer, I've completed 12 projects with strong client ratings clients continue working with me because of my clear communication, reliability, and attention to detail throughout the project lifecycle. I'd be glad to discuss your requirements in more detail and provide a clear plan along with a realistic timeline. I'm available to start immediately and can commit the necessary time to ensure smooth, timely delivery. Looking forward to the opportunity to work together. Best! Abbas
$66 SGD in 3 days
0.0
0.0

Hello, I can help secure your AWS S3 environment from assessment through deployment. I’ll perform comprehensive penetration testing, vulnerability scanning, and IAM/access-control reviews to identify misconfigurations and exploitable risks. I’ll provide a clear test plan, detailed findings with risk ratings and reproduction steps, plus a prioritized remediation roadmap. I can then implement the agreed fixes using Terraform, CloudFormation, or AWS CLI, covering bucket policies, IAM roles, lifecycle rules, and deployment workflows. Finally, I’ll conduct verification testing to ensure critical/high-risk issues are resolved and permissions follow least-privilege principles. I’m ready to start immediately and deliver clean, secure, production-ready results.
$30 SGD in 7 days
0.0
0.0

Hi, I’d be happy to help you with daily laptop maintenance and keep your system running smoothly. I can dedicate 60–90 minutes each day at a mutually convenient time. I can assist with OS and driver updates, file organization, software installation/configuration, basic troubleshooting, performance checks, and general system maintenance. I understand the importance of reliability and careful handling when working remotely on someone else’s computer. I will follow your instructions closely, avoid unnecessary changes, and provide a short report after each session so you always know what was completed. I’m comfortable using remote-access tools such as AnyDesk or TeamViewer and can maintain a consistent daily schedule. Your $250/month budget works for me, and I’m available to start this week. Looking forward to working with you.
$45 SGD in 7 days
0.0
0.0

Hi, I can test and harden your S3 deployment. My approach: review the bucket configuration for public exposure and misconfigured policies, run access and permission checks, validate encryption at rest and in transit, and then deploy the fixes with proper versioning, logging and least-privilege IAM. I will deliver a short report of what was found and what was changed, so you have a clear audit trail. Could you confirm whether this is a single bucket or multiple, and whether the bucket is currently live or still in testing?
$40 SGD in 3 days
0.0
0.0

Hey, I can help assess and harden your AWS S3 environment with a focus on access control, bucket policies, IAM permissions, secure deployment and configuration issues. You can review my work here: https://www.freelancer.pk/u/UmairBuildsAI My experience includes full-stack development, APIs, cloud deployments, automation and backend security practices. I can review bucket policies, IAM roles, public-access settings, encryption, lifecycle rules and related configurations, then implement the agreed remediation through AWS CLI or infrastructure-as-code. I’ll also provide a clear findings report and verification results, while keeping testing within your authorized AWS environment. Could you please confirm whether your infrastructure is currently managed through Terraform/CloudFormation, or should I first assess the existing AWS configuration and prepare the deployment workflow accordingly? Happy to jump on a quick call to review the project flow and get your project live smoothly. Best Regards, Umair
$30 SGD in 7 days
0.0
0.0

Hello I'm a tech PM working in Germany and have has lots of testing experiences with amazon services, it would be nice if you trust me with this task. my turn around time is 24/48 hours ping me if interested
$55 SGD in 2 days
0.0
0.0

Hi, I can conduct an end-to-end security assessment and hardening for your AWS S3 estate to ensure zero unauthorized exposure and strict least-privilege access. My Execution Plan: 1. Discovery & Testing: Audit all S3 buckets using Prowler, ScoutSuite, and custom AWS CLI scripts. Test for public read/write permissions, ACL misconfigurations, and IAM over-privileging. 2. Security Controls Audit: Verify S3 Block Public Access, TLS-only enforcement, default encryption (SSE-KMS/SSE-S3), lifecycle rules, and access logging. 3. Deliverables: • Assessment Report with findings, risk ratings, and reproduction PoCs. • Prioritized remediation roadmap. • Ready-to-deploy AWS CLI scripts and Terraform/CloudFormation templates to patch policies into production. • Final verification run confirming all critical/high issues are resolved. Ready to begin immediately once read access is provided.
$50 SGD in 6 days
0.0
0.0

I can handle the full S3 security lifecycle—from assessment through remediation and final verification. I’ll thoroughly review every bucket, IAM role, bucket policy, ACL, encryption setting, public-access configuration, logging, lifecycle rules, and cross-account access. I’ll perform authorized security testing and configuration scanning, document reproducible findings with risk ratings, and provide a prioritized remediation plan. I’ll then implement approved fixes using Terraform, CloudFormation, or AWS CLI, with secure deployment workflows and least-privilege access controls. A final verification will confirm that all critical and high-severity findings are resolved or formally accepted
$45 SGD in 7 days
0.0
0.0

Dear Client, I specialize in cloud security assessments and secure deployment workflows with hands-on expertise in AWS. Your project requires both discovery and implementation, and I can deliver a structured, reliable process that ensures your S3 estate adheres to least-privilege principles. ? My Approach Testing Phase: Penetration testing, vulnerability scanning, and detailed access-control reviews using AWS-native and industry-standard tools. Reporting: Clear documentation of findings with risk ratings, reproduction steps, and a prioritized remediation roadmap. Implementation: Updating IAM roles, bucket policies, lifecycle rules, and deployment workflows via CloudFormation/Terraform or AWS CLI scripts. Verification: Final security run to confirm all critical/high-risk issues are resolved. ? Why Choose Me Proven track record in AWS security hardening and compliance-focused deployments. Strong ability to move seamlessly from assessment to remediation, ensuring fixes are production-ready. Commitment to precision, transparency, and delivering actionable results. I’m confident I can secure your S3 environment quickly and thoroughly. Let’s make your estate resilient and compliant. Best regards,
$45 SGD in 3 days
0.0
0.0

Hi, I'm Fernando from FCyberSecurity LLC (US-based cybersecurity firm). I can handle both phases of this project: Phase 1 - Security Assessment: manual pentest of your S3 buckets (public access, misconfigured ACLs/policies, bucket takeover risks), automated vulnerability scanning, and a full IAM review (over-privileged roles/users, unused keys, policy misconfigurations). Phase 2 - Implementation: harden bucket policies, least-privilege IAM roles, lifecycle rules, and deliver updated CloudFormation/Terraform so everything stays reproducible and auditable going forward. Deliverable: a severity-ranked findings report plus the hardened IaC code. Quick scoping questions: how many S3 buckets/accounts are in scope, and do you already use Terraform or CloudFormation, or should I set up the IaC structure from scratch? Ready to start immediately.
$50 SGD in 5 days
0.0
0.0

FAISALABAD, Pakistan
Payment method verified
Member since Sep 30, 2020
₹600-1500 INR
$30-250 USD
$10-30 AUD
$30-250 USD
$10-30 USD
$750-1500 USD
$30-250 USD
₹1500-12500 INR
$25-50 USD / hour
$25-50 USD / hour
₹1500-12500 INR
₹12500-37500 INR
₹1500-12500 INR
$15-25 USD / hour
£500-1000 GBP
$30-250 NZD
₹12500-37500 INR
$10-30 USD
$3000-5000 USD
$10-30 USD
$25-50 USD / hour
₹1250-2500 INR / hour
₹1500-12500 INR
₹1500-12500 INR
$1500-3000 USD