Is your feature request related to a problem? Please describe.
Currently, l3 resource atlas-basic-private-endpoint doens't allow changing securitygroup used for ec2.CfnVPCEndpoint resource.
Describe the solution you'd like
Allow changing securitygroup for the encapsulated resource ec2.CfnVPCEndpoint.
Describe alternatives you've considered
Using l1 resources and configuring it all manually.
Additional context
Using l1 resources gives more control but takes a ton of convenience away.