nestor@fleitas:~$ _
nestor@fleitas:~$ whoami

AI Systems Architect
& DevSecOps Engineer

I design secure platforms where cloud infrastructure, DevSecOps pipelines and autonomous AI agents operate under identity, authorization, policy and audit controls.

Néstor Fleitas  |  Chubut, Argentina · Remote  |  available

Agentic AI AI Governance Kubernetes AWS · Azure · GCP DevSecOps NexusOS
▼ scroll

About Me


Néstor Fleitas
Name Néstor Fleitas
Location Chubut, Argentina
Work mode Remote / Hybrid
Email
📱 WhatsApp

// career path

Over 15 years in software engineering. I started as a Java backend developer working on SOA integration for banking and telecom (Banco Credicoop, HSBC, Telefónica, Telecom): distributed systems, service buses and integration architecture were my technical foundation.

That foundation evolved into cloud and operations: SRE at Equifax, mobile CI/CD at Flux IT, platform architecture at Ingenia, data & cloud engineering at Clarín, and DevSecOps at Allianz, where I worked from the security team on the corporate adoption of generative AI: secure development practices, access controls and LLM risk. Today I run DevOps platforms in banking (Banco Pichincha, Banco Itaú) with AWS, Azure, OpenShift, Terraform and GitLab CI.

That path converges in NexusOS: a governance platform for autonomous AI systems. I don't just build agents — I build the identity, authorization, policy, risk and audit layer that lets them operate safely in real environments. The core idea: AI proposes, governance decides.

Areas of Expertise


Three connected domains: platform and security experience is the foundation that makes it possible to design governed, production-ready autonomous AI systems.

A. AI Systems & Governance

Architecture of agentic systems and the control layer that makes them trustworthy.

Agentic Systems Multi-Agent Architecture AI Governance Policy Enforcement Authorization Capability-Based Security Human-in-the-loop Provider Routing Auditability Prompt Injection Mitigation Verification Observable Autonomous Systems

B. DevOps, Platform & Cloud

Infrastructure and automation applied in banking, insurance, telcos and media.

AWS Azure GCP Kubernetes Docker Terraform OpenShift CI/CD GitLab CI Jenkins Azure DevOps Infrastructure as Code Platform Engineering Observability

C. Security & Software Engineering

Security across the software lifecycle, on top of a backend and architecture foundation.

DevSecOps Secure SDLC SAST / DAST / SCA SonarQube GitHub Advanced Security Wazuh Java Python Bash REST APIs Distributed Systems Backend Architecture

NexusOS


"AI proposes. Governance decides."

The problem

AI agents can already read databases, write to repositories and modify infrastructure, but most frameworks execute first and audit later: no audit trail, no approval workflow, no risk classification, and no identity model that answers who authorized what.

The approach

NexusOS is a governance and authorization layer for AI agents. Every capability goes through a pipeline of mandatory gates before execution: no shortcuts, no bypasses, and signed evidence for every decision. It is provider-neutral: governance is not rebuilt when you switch models.

// governance pipeline

If any gate fails, execution is denied, the reason is logged and the audit record is still written. If the audit cannot be written, execution is denied as well.

✓ Implemented

  • Provider-neutral identity verification (Local, Keycloak, Azure Entra, LDAP)
  • Policy evaluation with signed evidence (HMAC-SHA256)
  • Risk classification: read-only / reversible write / irreversible write
  • Per-operator, capability-scoped permission grants
  • Append-only audit chain with prevHash linking
  • 102 governed capabilities · 10 gates · 1,300+ test cases

⚡ In progress

  • Incremental execution enablement, starting with low-risk, reversible actions
  • Public-key signing for audit evidence (currently symmetric HMAC)

Use cases

  • Read-only infrastructure queries with operator identity and namespace scoping
  • AI-generated pull requests with a signed human approval before merge
  • Ticket automation and security operations with critical actions blocked until approval

Projects & Case Studies


Governed integrations — Nexus Desktop & Senses

Agent integrations with Desktop, voice, Telegram, HTTP, Linux, Windows, Docker, Kubernetes, Git and logs, running under the NexusOS governance pipeline with multi-provider LLM routing.

Secure generative AI adoption

At Allianz Argentina, from the security team: assessment of secure development practices, access controls and LLM risk in the corporate rollout of generative AI; CI/CD security with Jenkins, SonarQube and GitHub Advanced Security.

Banking DevOps platforms

Infrastructure as code on Azure with Terraform and containers on OpenShift 4 (Banco Pichincha); platform administration and GitLab CI pipelines on AWS (Banco Itaú). CNCF framework evaluation in the DevOps chapter.

Data & Cloud in media

At Clarín (AGEA): GCP integration with Elastic Cloud (Pub/Sub, Dataflow, Airflow), Java connector development, EKS clusters with CDK and Node.js microservices.

Experience


// work history

2026
Present

Nexus AI — NexusOS

Founder & CTO · AI Systems Architect

Design and development of NexusOS, a governance and authorization platform for AI agents: a 10-gate pipeline (identity, policy, permission, risk, enforcement, audit), an HMAC-signed audit chain, and governed integrations for infrastructure, code and operations.

FEB 2026
Present

Banco Itaú

DevOps — Contractor

Administration of DevOps/DevSecOps infrastructure and platforms. CI/CD pipeline and deployment automation, infrastructure as code, and collaboration with technical teams on incidents and improvements. Stack: AWS, GitLab CI.

DIC 2024
FEB 2026

Banco Pichincha

DevOps — Freelance

Azure infrastructure with Terraform and container management on OpenShift 4. CNCF framework evaluation in the DevOps chapter and CI/CD process optimization in banking environments.

JUL 2024
MAY 2025

Allianz Argentina

DevSecOps

Worked from the security team on the corporate rollout of generative AI: assessment of secure development practices, access controls and LLM risk. CI/CD security with Jenkins, SonarQube and GHAS. AWS EKS infrastructure with Terraform. Security training for internal and external teams.

FEB 2024
JUL 2024

Arkho — Chile

Cloud Engineer — Contractor

AWS infrastructure with CloudFront, S3 and RDS. Backend with Node.js microservices on an EKS cluster. CDK, CodeBuild, CodePipeline, CodeCommit and Docker.

OCT 2022
MAR 2024

Clarín — AGEA

Data & Cloud Engineer

GCP integration with Elastic Cloud: Pub/Sub, Dataflow, Airflow. Docker and Kubernetes. Java connector development, AWS EKS with CDK (VPC, ELB) and Node.js microservices.

ABR 2022
SEP 2022

Ingenia

Technology Architect / SRE / DevSecOps

Geopagos: architecture design and AWS infrastructure with Kubernetes, Terraform, Airflow and GitLab. Mercantil Andina: new platform design on Azure with AKS, Terraform, Azure DevOps and Bitbucket.

JUL 2021
ABR 2022

Flux IT

DevOps Mobile

CI/CD for Android and iOS apps with Docker, Jenkins and Azure DevOps across GCP, AWS and Azure. Integration with SonarQube and Browserstack.

FEB 2020
JUN 2021

Equifax

SRE — DevOps

Site Reliability Engineering: Docker, Ansible, Apache, Tomcat, Nagios, Red Hat Linux, Nginx, Jenkins, Terraform and Kubernetes on GCP.

2012
2022

Java / SOA era — banking & telcos

Backend & Integration Engineer · Architecture

Backend and integration architecture foundation: Telecom (SOA with OSB 12c, DataPower, Jenkins; technical lead and configuration manager 2018–2020, plus production deployment support off-hours and on weekends through late 2022), HSBC (Sr Java, IBM ESB, 2017–2018), Banco Credicoop (Java in the Architecture team; open source research: CouchDB, Node.js, ELK, Jenkins, 2014–2017), Telefónica/Movistar (Java SOA/OSB consultant, WebLogic, Spring, 2012–2014).

2008
2009

Accenture

Cobol Developer

Cobol programming on mainframe (JCL, DB2).

// education & certifications

AWS Cloud Practitioner

Amazon Web Services

Red Team · OSINT · DevSecOps & Cloud Security

Hackademy (2022–2025)

CyberOps

SeaCCNA (2024)

DevOps · Data Science

MundoSE (2022–2023)
2013

Industrial Engineering

U.T.N. — Facultad Regional Buenos Aires
2002

IT Technician

E.E.T. N° 9 Ing. Torcuato Di Tella — Avellaneda

Services


I work with platform, security and technology teams that need to adopt AI without losing control, or take their DevOps/DevSecOps practice to the next level.

AI Systems Architecture

Design of production-ready agentic and multi-agent systems: architecture, provider routing, observability and execution boundaries. For organizations that are past the pilot stage and need AI to operate reliably.

AI Governance Assessment

Assessment of your agent and LLM governance posture: identity, authorization, risk classification, approvals and audit. For CISOs and compliance teams that need evidence, not promises.

Secure Agentic AI Adoption

Guidance for adopting generative AI and agents with controls from day one: secure development, prompt injection mitigation and human-in-the-loop for critical actions.

DevSecOps Consulting

Security integrated into the lifecycle: SAST/DAST/SCA in pipelines, Secure SDLC, CI/CD hardening. Applied experience in banking and insurance.

Cloud & Platform Architecture

Architecture and infrastructure as code on AWS, Azure and GCP: Kubernetes, OpenShift, Terraform and CI/CD automation for platforms that scale.

Architecture Review & Technical Advisory

Architecture review and technical guidance for platform, security and AI decisions: an external senior perspective before committing investment.

Security & DevOps News


Feed generated automatically by my own pipeline (GitHub Actions + RSS + scoring), updated daily.

news.log — top 3 — cargando...
$ cat assets/data/news.json | jq '.items[]'

Contact


Job opportunities

AI Systems / Platform / DevSecOps Architecture roles and senior DevOps, SRE or Platform Engineering positions. Remote from Argentina.

Let's talk about your search

Consulting & NexusOS

Secure AI adoption, agent governance, DevSecOps, or a NexusOS walkthrough for your technical team.

Schedule a conversation