AWS Terraform Engineer for a HIPAA-Aligned Serverless Backend (Cognito, Lambda, Bedrock)
We are a US consulting firm that builds operational and AI systems for growing companies. We are looking for qualified AWS engineers to build the secure backend for a small US healthcare practice, and we are hoping to find someone we keep working with on future projects.
**What you would build (Terraform, one US region):**
- Private VPC across 2 AZs, no public IPs, VPC endpoints for AWS services
- KMS customer-managed keys with rotation, Secrets Manager
- CloudTrail audit trail into an S3 bucket that cannot be deleted (Object Lock, 6-year retention), including data events on sensitive stores
- AWS Config rules, CloudWatch alarms to SNS, and backups for the data store and logs
- Least-privilege IAM, a cross-account deploy role, and a documented break-glass procedure
- Cognito with MFA required and role groups, designed so a second user type can be added later without reworking auth
- API Gateway with a JWT authorizer, and Lambda (Node.js) inside the private VPC
- AI chat plumbing on Amazon Bedrock: streamed responses, full conversation history in DynamoDB keyed to a person or team space, a set retention period, and a stubbed data-retrieval step in the handler. Model access sits behind a flag and is off at handover
- A test proving no message content reaches any log
- Ephemeral dev environment, production profile, CI checks (checkov or tfsec, terraform test)
- Deploy to the client's AWS account, then runbook, architecture diagram, and a frozen OpenAPI contract for our frontend team
**Not in scope:** the frontend (we build it), reporting or BI tools, EDI integrations, patient records.
**No real patient data at any point in this contract.** Everything is built and accepted on synthetic data.
**How we work:** fixed-price milestones, code in our GitHub repository from the first commit, short weekly check-ins. Shortlisted candidates might get a small paid technical review task before we award the build. Target start is early October.
In your proposal, tell us your hour estimate for the scope above and which line you think carries the most risk.