The stack you're describing (multi-cloud Terraform across AWS/GCP/Azure handling law enforcement evidence) is genuinely complex to secure from the ground up — especially with the compliance exposure that comes with CJIS-adjacent data.
One thing worth thinking about before the new hire starts: the first infra person at a bootstrapped company almost always walks into cloud credentials that are broader than needed and Terraform state that's never had a security pass. Getting a baseline done before onboarding gives them a clean starting point and avoids inheriting someone else's decisions as their first task.
Happy to talk through the infra side if useful — I work with teams at this stage on exactly this.
One thing worth thinking about before the new hire starts: the first infra person at a bootstrapped company almost always walks into cloud credentials that are broader than needed and Terraform state that's never had a security pass. Getting a baseline done before onboarding gives them a clean starting point and avoids inheriting someone else's decisions as their first task.
Happy to talk through the infra side if useful — I work with teams at this stage on exactly this.