I will build hipaa or soc2 compliant cloud infrastructure
Certified DevOps Specialist, DevSecOps, Kubernetes, SOC2, HIPAA, Terraform
About this Gig
I build AWS cloud infrastructure that meets HIPAA and SOC2 compliance controls. I have helped startups pass audits for fintech platforms and built HIPAA compliant environments for health tech companies. I build these controls from the beginning so your audit is clean and stress free.
Compliance controls I deploy on AWS:
Security: CloudTrail audit logging across all regions and AWS Config for drift detection and GuardDuty threat monitoring and VPC Flow Logs
Encryption: KMS keys for all database volumes and RDS databases and S3 storage
Access Control: Strict IAM least privilege rules and multi factor authentication checks and Secrets Manager for credentials
Data Protection: Public bucket blocking on S3 with active access logging and ALB load balancers terminating HTTPS traffic
Containers: Hardened EKS Kubernetes pods running as non root with network traffic policies
If you are preparing for a Vanta or ScoutSuite audit I resolve outstanding findings and prepare your evidence package containing configuration exports and security policies for your auditor.
Message me before ordering to discuss your framework and stack and audit timeline.
My Portfolio
Other DevOps Engineering Services I Offer
FAQ
What is the difference between SOC2 Type I and Type II?
Type I is a point in time assessment of your controls today. Type II covers a period of time like six months and verifies controls operated continuously. Startups usually start with Type I.
Do you work with compliance tools like Vanta or Drata?
Yes. I have resolved outstanding security findings directly in Vanta and Drata and ScoutSuite. I will implement the controls so they show as passing in your compliance dashboard.
Can you help prepare for a scheduled audit?
Yes. Tell me when the audit starts and I will check your environment to implement the missing compliance controls before the formal review begins.
We are on EKS. Does that change the scope?
Kubernetes requires container level security controls. I set up network policies and non root container profiles and resource limits to satisfy EKS security compliance.

