A tech startup is deploying a financial application on an Amazon EC2 instance. This application needs to securely retrieve credentials to connect to a backend Amazon RDS PostgreSQL database. A solutions architect is asked to store these credentials using AWS Systems Manager Parameter Store with encryption. What is the most appropriate and secure way to grant the application access to the encrypted credentials stored in Parameter Store?