
Suljettu
Julkaistu
Maksettu toimituksen yhteydessä
I am running a production web application on AWS using Ubuntu EC2 and Docker. The application is already secured at the backend level with authentication, rate limiting, JWT session management, GDPR endpoints, and security headers. Now I need an experienced engineer to harden the infrastructure and deployment environment to production-grade security standards. This is not a basic setup task. I am looking for someone who understands real-world security risks and can implement best practices across AWS, Linux, and Docker. Current Setup Ubuntu EC2 instance Docker-based application (Node/FastAPI stack) HTTP and HTTPS exposed Basic security already implemented at application layer Scope of Work AWS Layer Set up Application Load Balancer with HTTPS (ACM) Restrict EC2 access to ALB only using security groups Implement AWS WAF with basic protection and rate limiting Enforce IMDSv2 Review and tighten IAM roles and permissions EC2 / OS Layer Harden Ubuntu server Disable or restrict SSH access and configure AWS SSM access Configure firewall (UFW) Enable automatic security updates Docker Layer Review docker-compose and Dockerfiles Remove any privileged configurations Ensure containers run as non-root Restrict container capabilities Ensure only reverse proxy exposes ports Isolate internal services (DB, Redis, etc.) Secrets & Config Move sensitive data out of .env files where possible Integrate AWS Secrets Manager or SSM Parameter Store Ensure secure handling of JWT secrets and credentials Logging & Monitoring Set up CloudWatch logging for application and system Basic alerting for suspicious activity (failed logins, spikes, etc.) Validation Provide a checklist of changes implemented Identify remaining risks or recommendations Optional light penetration testing Deliverables Hardened AWS architecture Updated Docker configuration Security checklist and documentation Clear explanation of changes made Requirements Strong experience with AWS (EC2, ALB, WAF, IAM) Strong experience with Docker security and container hardening Experience securing production web applications Ability to explain decisions clearly
Projektin tunnus (ID): 40305480
91 ehdotukset
Etäprojekti
Aktiivinen 22 päivää sitten
Aseta budjettisi ja aikataulu
Saa maksu työstäsi
Kuvaile ehdotustasi
Rekisteröinti ja töihin tarjoaminen on ilmaista
91 freelancerit tarjoavat keskimäärin $268 USD tätä projektia

Hi there, I will harden your AWS+Ubuntu+Docker production stack to production-grade standards , I’ve implemented ALB+ACM, WAF, IMDSv2, and container hardening for Node/FastAPI stacks in similar environments and will apply those proven controls here. - Deploy ALB with HTTPS (ACM), AWS WAF rules and security-group rule to allow ALB→EC2 only - Enforce IMDSv2, tighten IAM roles, enable CloudWatch logs + alerting for spikes/failed logins - Harden Ubuntu (UFW, automatic security updates, SSM instead of open SSH), audit Dockerfiles/docker-compose, remove privileged flags and enforce non-root containers - Deliver security checklist, change documentation, and optional light penetration test; include rollback/validation steps and staged deploy to avoid downtime Skills: ✅ Amazon Web Services (EC2, ALB, WAF, IAM) ✅ Docker, docker-compose, Dockerfile hardening ✅ IAM least-privilege & secrets workflow (Secrets Manager / SSM) ✅ Ubuntu hardening, UFW, AWS SSM ✅ Logging/alerting with CloudWatch, intrusion anomaly monitoring Certificates: ✅ Microsoft® Certified: MCSA | MCSE | MCT ✅ cPanel® & WHM Certified CWSA-2 I’m available to start immediately , Do you manage this AWS account with IaC (Terraform/CloudFormation) and can you provide an admin IAM role plus temporary SSM access so I can validate and deploy changes? Best regards,
$150 USD 1 päivässä
6,9
6,9

Hi, We’ve secured multiple production-level web apps on AWS, including a large-scale product with 1 million users. We implemented advanced security measures like WAF, IAM role restrictions, and server hardening, along with CI/CD pipelines for automated security updates. As a full-stack developer with 15 years of experience, I’ve worked extensively with Node.js, PHP, Python, and modern front-end frameworks. I’m also a certified AWS solution architect, well-versed in both server management and web application security. In addition to server hardening, I can enhance your app’s security at the code level by identifying and fixing vulnerabilities such as SQL injection and XSS. Let’s schedule a 10-minute introductory call to discuss your project in more detail and see if I’m the right fit. I usually respond within 10 minutes. I’m eager to learn more about your exciting project. Best regards, Adil
$164,08 USD 7 päivässä
7,0
7,0

As an experienced Network, Cybersecurity, VoIP and System Engineer with over 10 years of professional experience and proficiency in Linux, Network Security, System Administration, and Ubuntu - I embody the ideal candidate you're seeking for this project. My work history is a testament to my detailed understanding of AWS (EC2, ALB, WAF, IAM), Docker security and container hardening; which are all critical components for the upgrade to your infrastructure's security. I have a proven track record in securing production web applications by deploying best practices that include all layers - AWS, Linux and Docker. I bring to the table not only technical expertise but also collaborative skills demonstrated by strong vendor partnerships with industry leaders such as Cisco, VMware, IBM among others. In an inherently complex project like yours that spans different layers and systems - good communication is essential. My dedication to clearly explaining decisions and providing comprehensive documentation will give you full visibility into the changes implemented while ensuring a smooth working relationship. I guarantee you 100% project delivery within your timeframe. Thank you for considering my candidacy.
$180 USD 3 päivässä
7,2
7,2

Hello, your aim to harden an AWS Ubuntu Docker deployment to production-grade security is exactly the kind of challenge I excel at. This is my speciality - turning complex risk requirements into practical, auditable improvements that protect uptime and customer trust. I'm Iosif Peterfi, 15+ years delivering secure web apps for PMs across Europe. I translate risk into clear plans, measurable outcomes, and hands-on results. Your scope aligns with my approach: I'll tighten the AWS layer with an Application Load Balancer and TLS, restrict EC2 access to the ALB, deploy a basic but effective WAF, enforce IMDSv2, and review IAM roles. At the OS level, I'll harden Ubuntu, minimize SSH exposure, enable SSM, set up a disciplined firewall, and enable automatic security updates. For Docker, I'll review the compose files and images, remove privileged configurations, run containers non-root, limit capabilities, ensure only the reverse proxy exposes ports, and isolate internal services such as DB and cache. Secrets and config will move sensitive data to managed stores, with JWT secrets protected. Logging and monitoring will feed CloudWatch and set alerts for anomalies. I'll deliver a concrete validation checklist, identify residual risks, and provide practical recommendations; optional light penetration testing can be included.
$4 200 USD 21 päivässä
6,8
6,8

With my 8 years of experience encompassing Linux administration, software engineering, and web development, I am the perfect fit for your project. My proficiency in Ubuntu EC2, Docker based applications, and AWS make me an ideal candidate to secure your AWS infrastructure according to production-grade standards. I possess an extensive skill set in AWS (EC2, ALB, WAF, IAM), Docker Security & Container Hardening, and Web Security which will arm your environment against real-world security risks.
$140 USD 1 päivässä
6,6
6,6

Greetings! I have 16+ years of experience working as a Linux System Admin and 4+ years of experience working as a Devops. I will best secure your infra and application at aws as per your need now. Give me a chance to work with you and I am sure we will have a long term relationship in IT management. Thanks Vivek Sharma
$133 USD 7 päivässä
6,4
6,4

Hi, I have 8+ years of experience working with AWS cloud infrastructure and services, including EC2, S3, Lambda, IAM, RDS, CloudFront, Route 53, SES, SQS, SNS, CloudWatch, and API Gateway to build scalable, secure, and reliable environments. I handle server deployment, S3 storage setup, database management, email services with SES, security configuration, monitoring, performance optimization, and automation workflows. I also have experience with AWS migrations, including moving S3 buckets, EC2 instances, EBS volumes, and RDS databases between accounts or environments with minimal downtime and no data loss. Please share your requirements to proceed. Thank you
$180 USD 1 päivässä
6,2
6,2

Hi There, I can harden the infrastructure and deployment environment to production-grade security standards. I am a Server administrator having more than 10+ years of experienced in the same domain. Thanks Ashish A.
$250 USD 3 päivässä
6,3
6,3

Worked with all kind of servers and all panels since 2007 And currently working as linux system administrator If you need to start as soon as possible contact me And tell me more details about what you want to Tell the time and cost accurately, please contact me now, looking forward to work with you Best regards
$50 USD 1 päivässä
5,6
5,6

With a strong background in AWS and DevOps engineering, I am confident in providing you with the secure and hardened environment that your production web application deserves. My experience includes a full range of security strategies-from setting up Application Load Balancer with HTTPS (ACM) to hardening Ubuntu server, I understand every layer you're concerned about. Additionally, my expertise in securing and deploying containerized applications on Kubernetes platforms further bolsters my Docker security skills. My skill set doesn't limit me to a "basic setup task" as mentioned in your project description. I have proficiency in Node.js, Python, PHP; Terraform, CloudFormation, etc., which means not only will you get an updated Docker configuration but a hardened AWS architecture that clearly aligns with your project goals. Furthermore, as an AWS-certified professional with hands-on experience in integrating AI/ML services for intelligent automation- verification of JWT secrets or securing sensitive data would be a standard practice for me. In conclusion , my comprehensive toolkit , deep understanding of real-world security risks & the ability to explain decisions clearly-make me the ideal choice for maximizing your project's security environment.
$250 USD 7 päivässä
5,4
5,4

Hi, To harden your infrastructure and deployment environment to production-grade security standards, I will review your current setup and implement best practices across AWS, Linux, and Docker. I have strong experience with AWS services like EC2, ALB, and WAF, as well as Docker security. I will ensure your application is secure by setting up the Application Load Balancer, restricting EC2 access, and reviewing your Docker configurations. Could you please clarify if there are any specific compliance requirements or security standards you want to follow? Also, if you have any existing documentation or access details, please share them so we can get started. Thanks!
$420 USD 14 päivässä
5,6
5,6

Hi, With 16+ years of experience in AWS, DevOps, and infrastructure security, I specialize in hardening production environments across AWS, Linux, and Docker. I understand you need end-to-end security hardening for your Ubuntu EC2 + Docker setup, not just basic configuration. For your project, I will: • Configure ALB with HTTPS (ACM) and restrict EC2 access via security groups • Implement AWS WAF with rate limiting and protection rules • Enforce IMDSv2 and apply least-privilege IAM policies • Harden Ubuntu (SSH lockdown, move to SSM, UFW, auto updates) • Secure Docker setup (non-root containers, remove privileges, restrict ports, isolate services) • Move secrets to AWS Secrets Manager/SSM and secure credentials • Enable CloudWatch logging & alerts for suspicious activity You will receive a hardened architecture, updated configs, and a clear security checklist with recommendations. We can finalize the budget depending on the complexity of the environment. Best regards, SaD
$250 USD 7 päivässä
5,2
5,2

Hi there, I've been working as Cloud Architect for 5+ years focusing on AWS offerings and more than 10 years as System/Security Administrator. I'll be happy to help you with your hardening tasks and provide appropriate design documentation.
$120 USD 7 päivässä
5,3
5,3

Hi, We are AWS experts and certified and can do this. Please get in touch to start. Thanks
$200 USD 7 päivässä
5,5
5,5

Dear sir, I have rich experience in Docker, Docker Compose, AWS VPC, Subnets, Load Balancer, Auto Scaling, EC2, Route 53, ACM, CloudFront, WAF, etc. I can help you to harden the security of your AWS production environment as you specified in your job brief. Please contact me to discuss further details. Best regards, Swamy.
$300 USD 7 päivässä
5,6
5,6

Hello, I came across your project and found it truly interesting. With over eight years of hands-on experience in this field, I have successfully delivered high-quality solutions to clients worldwide. My dedication to excellence is reflected in the 180+ positive reviews from satisfied clients. I’d love to bring this expertise to your project and ensure outstanding results. However, I do have a few important points I’d like to clarify to align perfectly with your vision. Let’s connect via chat so I can share relevant examples of my past work. I look forward to hearing from you. Best Regards, Divu.
$250 USD 4 päivässä
5,1
5,1

** HUMAN PROPOSAL - NO BOT TEXT *** Hey, I can harden your AWS infrastructure and Docker deployment immediately. I noticed your Node and FastAPI application is running on an Ubuntu EC2 instance and you need to move beyond basic .env files to a production-grade setup using AWS Secrets Manager and an Application Load Balancer. Securing a public-facing application requires defense in depth. I will deploy an ALB with strict WAF rules and configure your Security Groups so your EC2 instance only accepts traffic from the load balancer. At the OS level, I will enforce IMDSv2, replace standard SSH with AWS Systems Manager Session Manager for secure access, and harden your Ubuntu environment. For your containers, I will rewrite your Dockerfiles to ensure all processes run as non-root users with dropped privileges and isolate your internal services like Redis so they are never exposed to the internet. Finally, I will route all system and container logs to CloudWatch for centralized monitoring and alerting. I guarantee I will support you until the entire infrastructure is hardened and runs perfectly without a single security vulnerability. Best, Ahmad
$220 USD 2 päivässä
4,8
4,8

Hi, I can harden your AWS + Docker setup to production-grade security standards. What I’ll do: • Setup ALB + HTTPS (ACM) and lock EC2 behind it • Configure AWS WAF + IAM (least privilege) + IMDSv2 • Harden Ubuntu (disable SSH → SSM, UFW, auto updates) • Secure Docker (non-root, no privileged access, isolated services) • Move secrets to AWS Secrets Manager / SSM • Setup CloudWatch logging + alerts Deliverables: • Hardened infrastructure + updated Docker config • Security checklist + documentation • Clear explanation + recommendations I have hands-on experience securing real production apps on AWS with Docker. — Pallvi Gupta
$70 USD 2 päivässä
4,7
4,7

Hello, I can help review and strengthen your AWS, Ubuntu EC2, and Docker deployment to ensure the infrastructure follows solid production best practices. I have experience working with AWS deployments for web applications and containerized services and can assist with improving the security posture of your current environment. I can configure an Application Load Balancer with HTTPS using ACM, tighten security groups so EC2 is only reachable through the ALB, review IAM permissions, and enable IMDSv2. On the server side, I can harden Ubuntu with UFW rules, restricted SSH access, automatic security updates, and improved system configuration. I will also review your Docker setup, ensuring containers run as non-root, removing unnecessary privileges, isolating internal services, and improving secret handling with AWS SSM Parameter Store or Secrets Manager. I will document all changes and provide a checklist of improvements and recommendations. Questions: Are you using Nginx or another reverse proxy inside Docker for routing? Should logging and alerts be implemented through CloudWatch or an external monitoring tool? Thanks, Asif
$250 USD 3 päivässä
4,4
4,4

This is right up my alley - I run production Node/FastAPI stacks on AWS with Docker daily. Currently managing multi-server setups with ALB, WAF, SSM-based access, and container hardening for a SaaS platform. Your scope is well-defined. I'd tackle it in order: AWS layer first (ALB + ACM, security groups, WAF rules, IMDSv2), then OS hardening (SSM instead of SSH, UFW, unattended-upgrades), then Docker lockdown (non-root containers, capability drops, network isolation). Secrets Manager integration for the .env cleanup would be the final peice. I can have this done in about 5 days. Happy to share specifics on approach. - Usama
$220 USD 5 päivässä
4,4
4,4

Thurles, Ireland
Maksutapa vahvistettu
Liittynyt kesäk. 8, 2006
$30-250 USD
$750-1500 USD
$30-250 USD
$30-250 USD
$750-1500 USD
$2-8 USD/ tunnissa
$30-250 USD
₹12500-37500 INR
$30-250 USD
$10-30 USD
₹600-1500 INR
$10-30 USD
₹1500-12500 INR
$30-250 USD
₹1500-12500 INR
₹12500-37500 INR
$15-25 USD/ tunnissa
$8-15 USD/ tunnissa
₹750-1250 INR/ tunnissa
€250 EUR
$10-30 AUD/ tunnissa
₹1500-12500 INR
€12-18 EUR/ tunnissa
$250-750 USD
₹70000-80000 INR