Ensure that ECS Service managed role doesn't have an overly permissive scope (Contains a wildcard)
Determine the specific resource scope needed by your ECS Service, and then craft IAM policies for these resources only, instead of full resource scope.
Updated 7 months ago