The media segregation allows your users to access your media in your AWS S3 bucket privately (not transiting on the public internet).
Add an S3 endpoint to your VPC
Set up S3 proxy
An S3 proxy is needed in your VPC to proxy the traffic from your network into the S3 VPC endpoint. See here for an example Docker image that could be run in your AWS account using AWS ECS running with AWS Fargate.