Skills
AWS architecture
Amazon VPC
Subnets and route tables
Security groups
AWS Database Migration Service
MongoDB change data capture
Data replication
Amazon Kinesis Data Streams
Amazon Kinesis Data Firehose
Amazon S3
S3 Object Lock
Amazon RDS for PostgreSQL
Amazon DynamoDB
AWS Secrets Manager
AWS Key Management Service
Infrastructure security
Change data monitoring
Data recovery procedures
Audit data architecture
Financial ledger design
Python
Terraform
GitHub Actions
AWS
AWS DMS
MongoDB
Amazon RDS
PostgreSQL
AWS KMS
Change Data Capture
Event-Driven Architecture
Summary
✨ AI‑Generated
An AWS solutions architect is sought to build a secure proof-of-concept data platform that captures database changes and routes them through a streaming architecture into immutable storage. You will configure cloud networking, replication tasks, monitoring, and recovery procedures while implementing relational and NoSQL targets for financial ledger and audit workloads. Strong expertise in AWS data services, security controls, event-driven architecture, and resilient data pipelines is essential.
Highlights
Design and implement a sophisticated AWS data architecture combining change-data capture, streaming, immutable event storage, financial ledger processing, and audit capabilities. The work offers hands-on experience with managed cloud services, secure credential handling, data recovery, and resilient event-driven systems.
Description
Build and configure the AWS PoV environment, including VPC, subnets, route tables, security groups and controlled outbound paths.
Implement AWS DMS for MongoDB CDC, including full load and ongoing change replication from the named secondary.Configure DMS endpoints, replication task, checkpointing, CDC latency monitoring and recovery procedures.Use AWS DMS to capture ActionEntry, Transaction, Movement and related in-scope collections.Route DMS output into Amazon Kinesis Data Streams as the single event log.Use Amazon Kinesis Firehose to write immutable raw change history into the S3 event store.Build an Amazon S3 event store with Object Lock governance mode, retention controls and replay-ready storage.Implement PostgreSQL RDS as the financial ledger target.Implement Amazon DynamoDB as the audit target, including single-table design, tenant-scoped keys, on-demand capacity and PITR.Use AWS Secrets Manager to store and control access to the read-only MongoDB CDC credential.Use AWS KMS customer-managed keys for RDS, DynamoDB, S3, Kinesis, Secrets Manager, pseudonymisation and report signing.Configure AWS CloudTrail for account-wide audit logging, including DynamoDB data events.Configure CloudWatch logging and metrics for DMS, pgAudit logs, tunnel status, alarms and operational evidence.Use VPC Flow Logs to evidence that MongoDB traffic only traverses the approved path.Implement AWS Site-to-Site VPN as the preferred encrypted transport path between AWS and the Hetzner private network.Define fallback direct controlled access if the VPN path is not available by the required P0 timeline.Build CloudWatch alarms, EventBridge rules and Step Functions workflows to suspend CDC automatically when source-impact thresholds are breached.Implement a Lambda-based source-impact guard to monitor canary reads, member role, oplog headroom and DMS latency.Run reconciliation workloads as containerised Python jobs on ECS Fargate, orchestrated by Step Functions and scheduled by EventBridge Scheduler.Run replay tooling as ECS Fargate batch jobs using S3 event-store data and RDS isolated replay schemas.Run JMeter load-testing harness on ECS Fargate against the ReThink-IT-provided MongoDB 5.0 replica set.Capture DMS lag, JMeter throughput and synthetic-event latency metrics through CloudWatch.Implement cross-tenant isolation using tenant-specific IAM roles and DynamoDB LeadingKeys conditions.Correlate isolation test cases with CloudTrail, DynamoDB data events and PostgreSQL pgAudit logs.Use Terraform 1.5+ for all AWS infrastructure provisioning.Use GitHub Actions with OIDC to deploy AWS infrastructure with protected environments, PR plans and apply-on-merge controls.Store Terraform state remotely with locking.Produce CloudTrail-derived reports proving zero manual AWS console-originated mutations.Build Athena-based reporting over CloudTrail logs for deployment evidence.Create Glue catalogue and Athena-queryable AI-ready export over partitioned Parquet data in S3.Implement S3 quarantine prefixes and alarms for non-conforming events.Build OpenSearch projection as an optional P3 component, with fallback to MongoDB and destruction after testing.Maintain AWS evidence artefacts including transport-security packs, reconciliation reports, event-loss reports, replay logs, lag reports, CloudTrail reports and teardown evidence.Perform AWS teardown and provide empty inventory, zero-billing and destruction confirmation evidence.Manage the AWS infrastructure cost envelope, including the Site-to-Site VPN cost within the stated EUR 150/month estimate.