Apply security at all layers. E.g. Subnet, ACL’s Ports that are open on the Load Balancer.
Enable tractability. E.g. ability to audit changes using load.
Automate responses to security events E.g. if you detect someone trying to brute force port 22 then it triggers an SNS notification for someone to look at.
Focus on securing your system E.g. you are responsible for securing your data, your application, and your OS.
Automate security best practices. E.g. look into “center for internet security” to understand how to harden images for Bastion jump boxes.