HealthTech Startup — AWS Security Audit
liveAWS Security Auditor — Freelance
Complete security audit of an AWS infrastructure hosting health data (GDPR Article 9). The infrastructure had major vulnerabilities: database in public subnet, no CloudTrail, plaintext secrets in CloudFormation, staging and production in the same AWS account, zero MFA. I delivered a detailed 36-finding report, a technical remediation plan with multi-account architecture, and a costed estimation (15-31K EUR) with two options. Security score mapped from 2/10 to a plan toward 8/10.
Key Results
36 vulnerabilities found, 9 critical
AWS Well-Architected security score: 2/10
ISO 27001 readiness: 18/100 — 30 major non-conformities
Database exposed to public internet
Stripe and API secrets in plaintext in CloudFormation
Multi-account AWS remediation plan delivered
Detailed technical estimation: 15-31K EUR depending on option
Non-technical CEO briefing delivered