Technically, stretching the system a bit, one could argue that we don't need backend software running on EC2 anymore, since everything can be a Lambda function with an associated HTTP endpoint to trigger it. I have been thinking about this a lot, and it could work if being locked into AWS is considered an acceptable risk.
For anything else more API-oriented (more authentication schemes, better security, more logging options, etc) I would suggest checking out Kong (https://github.com/Mashape/kong), which is pluggable with extra functionality and can work in front of the AWS API Gateway to enhance the REST-to-Lambda interface (and with any other API).