I design secure platforms where cloud infrastructure, DevSecOps pipelines and autonomous AI agents operate under identity, authorization, policy and audit controls.
Néstor Fleitas | Chubut, Argentina · Remote | available
// about
Over 15 years in software engineering. I started as a Java backend developer working on SOA integration for banking and telecom (Banco Credicoop, HSBC, Telefónica, Telecom): distributed systems, service buses and integration architecture were my technical foundation.
That foundation evolved into cloud and operations: SRE at Equifax, mobile CI/CD at Flux IT, platform architecture at Ingenia, data & cloud engineering at Clarín, and DevSecOps at Allianz, where I worked from the security team on the corporate adoption of generative AI: secure development practices, access controls and LLM risk. Today I run DevOps platforms in banking (Banco Pichincha, Banco Itaú) with AWS, Azure, OpenShift, Terraform and GitLab CI.
That path converges in NexusOS: a governance platform for autonomous AI systems. I don't just build agents — I build the identity, authorization, policy, risk and audit layer that lets them operate safely in real environments. The core idea: AI proposes, governance decides.
// expertise
Three connected domains: platform and security experience is the foundation that makes it possible to design governed, production-ready autonomous AI systems.
Architecture of agentic systems and the control layer that makes them trustworthy.
Infrastructure and automation applied in banking, insurance, telcos and media.
Security across the software lifecycle, on top of a backend and architecture foundation.
// featured project
"AI proposes. Governance decides."
AI agents can already read databases, write to repositories and modify infrastructure, but most frameworks execute first and audit later: no audit trail, no approval workflow, no risk classification, and no identity model that answers who authorized what.
NexusOS is a governance and authorization layer for AI agents. Every capability goes through a pipeline of mandatory gates before execution: no shortcuts, no bypasses, and signed evidence for every decision. It is provider-neutral: governance is not rebuilt when you switch models.
If any gate fails, execution is denied, the reason is logged and the audit record is still written. If the audit cannot be written, execution is denied as well.
// work
Agent integrations with Desktop, voice, Telegram, HTTP, Linux, Windows, Docker, Kubernetes, Git and logs, running under the NexusOS governance pipeline with multi-provider LLM routing.
At Allianz Argentina, from the security team: assessment of secure development practices, access controls and LLM risk in the corporate rollout of generative AI; CI/CD security with Jenkins, SonarQube and GitHub Advanced Security.
Infrastructure as code on Azure with Terraform and containers on OpenShift 4 (Banco Pichincha); platform administration and GitLab CI pipelines on AWS (Banco Itaú). CNCF framework evaluation in the DevOps chapter.
At Clarín (AGEA): GCP integration with Elastic Cloud (Pub/Sub, Dataflow, Airflow), Java connector development, EKS clusters with CDK and Node.js microservices.
// experience
// work history
Design and development of NexusOS, a governance and authorization platform for AI agents: a 10-gate pipeline (identity, policy, permission, risk, enforcement, audit), an HMAC-signed audit chain, and governed integrations for infrastructure, code and operations.
Administration of DevOps/DevSecOps infrastructure and platforms. CI/CD pipeline and deployment automation, infrastructure as code, and collaboration with technical teams on incidents and improvements. Stack: AWS, GitLab CI.
Azure infrastructure with Terraform and container management on OpenShift 4. CNCF framework evaluation in the DevOps chapter and CI/CD process optimization in banking environments.
Worked from the security team on the corporate rollout of generative AI: assessment of secure development practices, access controls and LLM risk. CI/CD security with Jenkins, SonarQube and GHAS. AWS EKS infrastructure with Terraform. Security training for internal and external teams.
AWS infrastructure with CloudFront, S3 and RDS. Backend with Node.js microservices on an EKS cluster. CDK, CodeBuild, CodePipeline, CodeCommit and Docker.
GCP integration with Elastic Cloud: Pub/Sub, Dataflow, Airflow. Docker and Kubernetes. Java connector development, AWS EKS with CDK (VPC, ELB) and Node.js microservices.
Geopagos: architecture design and AWS infrastructure with Kubernetes, Terraform, Airflow and GitLab. Mercantil Andina: new platform design on Azure with AKS, Terraform, Azure DevOps and Bitbucket.
CI/CD for Android and iOS apps with Docker, Jenkins and Azure DevOps across GCP, AWS and Azure. Integration with SonarQube and Browserstack.
Site Reliability Engineering: Docker, Ansible, Apache, Tomcat, Nagios, Red Hat Linux, Nginx, Jenkins, Terraform and Kubernetes on GCP.
Backend and integration architecture foundation: Telecom (SOA with OSB 12c, DataPower, Jenkins; technical lead and configuration manager 2018–2020, plus production deployment support off-hours and on weekends through late 2022), HSBC (Sr Java, IBM ESB, 2017–2018), Banco Credicoop (Java in the Architecture team; open source research: CouchDB, Node.js, ELK, Jenkins, 2014–2017), Telefónica/Movistar (Java SOA/OSB consultant, WebLogic, Spring, 2012–2014).
Cobol programming on mainframe (JCL, DB2).
// education & certifications
// services
I work with platform, security and technology teams that need to adopt AI without losing control, or take their DevOps/DevSecOps practice to the next level.
Design of production-ready agentic and multi-agent systems: architecture, provider routing, observability and execution boundaries. For organizations that are past the pilot stage and need AI to operate reliably.
Assessment of your agent and LLM governance posture: identity, authorization, risk classification, approvals and audit. For CISOs and compliance teams that need evidence, not promises.
Guidance for adopting generative AI and agents with controls from day one: secure development, prompt injection mitigation and human-in-the-loop for critical actions.
Security integrated into the lifecycle: SAST/DAST/SCA in pipelines, Secure SDLC, CI/CD hardening. Applied experience in banking and insurance.
Architecture and infrastructure as code on AWS, Azure and GCP: Kubernetes, OpenShift, Terraform and CI/CD automation for platforms that scale.
Architecture review and technical guidance for platform, security and AI decisions: an external senior perspective before committing investment.
// automated daily feed
Feed generated automatically by my own pipeline (GitHub Actions + RSS + scoring), updated daily.
// contact
AI Systems / Platform / DevSecOps Architecture roles and senior DevOps, SRE or Platform Engineering positions. Remote from Argentina.
Let's talk about your searchSecure AI adoption, agent governance, DevSecOps, or a NexusOS walkthrough for your technical team.
Schedule a conversation