Hi @treaves,
You don't have to be able to add CAA records to use Let's Encrypt, you just have to have an authoritative DNS server that does not return an error when asked about CAA. It's perfectly fine for the answer to be empty, it just can't be an error.
I don't believe Route53 is one of the authoritative servers that will return SERVFAIL for CAA lookups so you should be OK without having to do anything.