Better with iam identity center. Yes its possible create a permission set with only lambda read only assign it to a group and add this "user" in that group. :)