I will plan, build, and deploy a custom enterprise application


About this gig
Building on AWS is easy to start and expensive to fix if the foundation is wrong. Poor tenant isolation, missing observability, and manually configured resources compound over time and become harder to correct as your product grows.
This gig covers production-grade AWS infrastructure built correctly from the start. VPC with proper subnet segmentation, API Gateway with JWT authentication, serverless compute, relational and NoSQL data layers, KMS encryption, least-privilege IAM, and CloudWatch observability. Everything is provisioned in Terraform so deployments are repeatable and environments stay consistent.
For multi-tenant platforms, data isolation is enforced at every layer from the authentication token down to the database query.
Delivery includes complete architecture documentation and a CI/CD pipeline across development, staging, and production. The infrastructure is yours on day one, built to be maintained without deep AWS expertise.
AWS certifications held: Solutions Architect, Machine Learning Engineer, Developer, AI Practitioner, and Terraform Associate.
Get to know Kai Balciunas
AI Engineer
- FromUnited States
- Member sinceJun 2026
- Avg. response time1 hour
Languages
English, Spanish, Lithuanian
My Portfolio
FAQ
Who pays for the cloud infrastructure and services used during the build?
The client's payment method is placed on file with the cloud provider before any provisioning begins. All usage costs are billed directly to the client's account. There is no markup on cloud spend.
How do you approach security and data privacy across a project?
Security is designed in from day one. Every build includes encryption at rest and in transit, least-privilege IAM roles, secrets management, and audit logging. Compliance requirements like HIPAA are scoped and provisioned upfront.
How do you make architectural decisions around cost?
Cost architecture follows the client's priorities. High availability needs get redundant, always-on infrastructure. Cost-sensitive projects get serverless designs that charge only for actual usage. Tradeoffs are agreed upon during scoping.
What does the handoff process look like when the project is complete?
The client receives full architecture documentation and maintenance tutorials written for whoever owns the system going forward. Once deliverables are confirmed, credentials and admin access are transferred to the designated party.
When does your access to the system end and how is that handled?
Developer access is fully revoked after handoff. IAM roles are removed, temporary credentials are rotated, and cloud account access is relinquished. The client ends up with complete ownership and no residual developer access.
Will our team be able to maintain the system after delivery without deep cloud expertise?
Yes. Infrastructure is managed in Terraform so changes follow a predictable, code-driven process. Documentation and tutorials are written for the actual team taking ownership, not a hypothetical senior engineer.
How are scope changes handled mid-project?
Minor adjustments within the original scope are handled as part of normal delivery. Changes that materially expand scope are discussed openly and result in a revised timeline and cost estimate before any additional work begins.
Do you work with existing infrastructure or only greenfield builds?
Both. Greenfield builds start from scratch and are designed correctly from day one. Existing infrastructure engagements begin with an audit covering security, cost, and architecture before any changes are made to live systems.

