FEATMATE
backup Fixed Price

Encrypt 10 TB Health-Tech Data with Customer-Managed KMS, IRSA & Immutable Vault

Posted 11 months ago  ·  0 proposals


Budget

$2,100.00

Level

Senior

Location

Egypt

Posted

Sep 26, 2025

Proposals

0

Job Type

Fixed Price

Job Description

Overview:

You are General Counsel + CISO of a health-tech platform storing 10 TB of patient imaging + genomic data. HIPAA auditors just flagged SSE-S3 encryption as insufficient; they demand customer-managed keys, immutable storage, pod-level identity, signed URLs and 7-year WORM retention. Legal hold is active—deletion or tampering could trigger $1.5 M fine per record.

 Zero-Trust Security Outcomes

  • Customer-managed KMS CMK with annual rotation → no AWS root access.
  • S3 Object Lock Compliance Mode 7 years → even root cannot delete.
  • IRSA pod identity → Velero backup pod has no long-lived keys.
  • Signed URLs 15 min expiry for clinician downloads → zero anonymous access.
  • Pen-test + evidence package → auditor-ready ZIP + SHA-256 manifest.

Deep-Dive Engineering Scope

  • Multi-Region KMS Root-of-Trust
    • MRK (Multi-Region KMS CMK) deployed in eu-central-1 primary + eu-west-1 replica.
    • Key policy least-privilege : only Velero IRSA role + legal-hold Lambda.
    • Annual rotation enabled + CloudTrail KMS events → Glacier 7-year.
  • Immutable WORM Vault
    • S3 Bucket with Object Lock Compliance Mode 7 years + Legal Hold ON.
    • Bucket Policy explicit deny : DeleteObject + PutObjectAcl + s3:BypassGovernanceRetention.
    • S3 Inventory daily CSV → stored in separate audit account.
  • Pod-Level Identity (IRSA)
    • OIDC provider federated between EKS and AWS IAM.
    • Velero ServiceAccount annotated with IRSA role → zero AWS_ACCESS_KEY_ID in pod.
    • Session tagging : cost-centre, environment → CloudTrail identity.
  • Signed URL Downloader
    • Lambda (Python) generates presigned GET URL 15 min expiry + IP whitelist.
    • CloudFront WAF rate-limit 100 req/IP/5 min → prevents brute-force
    • Access logged to Centralized CloudWatch + S3 access logs.
  • Compliance Evidence Package
    • Pen-test scoped to backup endpoints → zero critical findings.
    • SHA-256 checksum manifest of every object → signed with GPG.
    • Legal-hold register (CSV) with object key, retention expiry, case ID.

Enterprise Deliverables

  • KMS key policy JSON + S3 bucket Terraform + IRSA role YAML.
  • Signed URL generator Lambda (zip) + Terraform module.
  • Evidence bundle: pen-test PDF, SHA-256 manifest, legal-hold CSV.
  • Board-level slide : risk before vs after, fine avoidance, audit timeline.
About the Client
Amira Youssef

Amira Youssef

Client  ·  Egypt

Related Jobs
$70.00 Hourly Senior 1 year ago

We are hiring a Business Continuity Planner to develop a comprehensive strategy for maintaining oper...

Risk assessment and analysis
View Job →
$65.00 Hourly MidLevel 1 year ago

We are looking for a Backup Automation Specialist to automate and optimize our data backup processes...

Backup automation for different backup types (e.g., file backup, database backup, application backup)
View Job →
$60.00 Hourly MidLevel 1 year ago

We are seeking a Data Recovery Expert to implement and manage data recovery solutions, ensuring data...

Data recovery tools and technologies
View Job →
$60.00 Hourly MidLevel 1 year ago

We are hiring a Backup Security Analyst to secure our backup systems, ensuring data integrity and pr...

Backup data encryption
View Job →

Login as a freelancer to apply

Amira Youssef

Amira Youssef

Offline

Egypt


Member Since
Oct 2024
Total Jobs Posted
6