Cloud/Infra Engineer (Infrastructure & Security) (Argentina)

Cloud/Infra Engineer (Infrastructure & Security) (Argentina)

30 jul
|
AceUp
|
Argentina

30 jul

AceUp

Argentina

Location: Remote (LATAM Only) | Contract Type: Full-Time Contractor

About AceUp

AceUp is an AI-powered coaching platform trusted by enterprise clients to develop their leaders. We're SOC2 Type II certified, a Techstars alum, and have made the Inc. 5000 three years running. We're now in the middle of an exciting shift — from tech-enabled coaching toward a true AI/SaaS platform, built around Ally, our AI coaching product, and its evolving multi-agent architecture.

The Opportunity

We're hiring our first dedicated SRE / SecOps Engineer to help us run this next chapter reliably and securely. You'll take hands-on, day-to-day ownership of production reliability, cloud infrastructure, and security posture across our Google Cloud Platform environment — where Ally's Python microservices run alongside our Ruby on Rails core, backed by AlloyDB, Cloud Storage, and Vertex AI.

You won't be figuring this out alone. You'll report to our Engineering Manager, and work closely with our AI Lead — both bring real infrastructure background, will actively review your architecture and security decisions, and have your back on the highest-stakes incidents. This is a role with real, immediate ownership and a real support system: built for someone ready to grow into running critical infrastructure independently.

The Tech Stack

- Cloud Provider: Google Cloud Platform (GCP) — fully migrated, no other clouds in production
- Compute: Cloud Run (primary), Cloud Functions where it fits. We don't run Kubernetes/GKE today — familiarity is a plus for future scaling conversations, not a requirement.
- Data: AlloyDB, Cloud Storage, Firestore/Firebase
- Infrastructure as Code: Terraform
- CI/CD: GitHub Actions, continuous deployment to staging/production
- Apps: Ruby on Rails (core platform), Python (AI/ML services), Node.js
- AI Platform: Vertex AI / Gemini (production inference), an emerging multi-agent orchestration and memory layer
- Observability: Datadog / GCP Cloud Monitoring / Sentry
- Security & Compliance: GCP IAM, VPC/network controls, Secret Manager, Cloud Armor, Auth0 (SAML/SSO), Vanta (SOC2)

What You'll Do Keep production reliable. Define and monitor SLIs/SLOs for our core APIs and AI inference endpoints, using synthetic checks and real-user monitoring to catch degradation before customers do. Build and lead our on-call rotation, shape incident response protocols, and run blameless post-mortems. Alex and Fede are your secondary escalation on critical incidents — you're the primary responder, not the only one.

Run and evolve our GCP infrastructure. Design, manage, and maintain our Terraform-defined infrastructure across Staging, Production, and any isolated AI/sandbox environments — networking, IAM baselines, and security controls included. Significant architecture changes get reviewed with Alex or Fede before they ship; day-to-day operation and iteration is yours to run.





Close a real cost gap. We've already identified concrete GCP savings — database configuration and underused regional resources among them — through a recent infrastructure audit. You'll close what's on the table and build the muscle to catch this kind of thing earlier: rightsizing, budget alerts, and spend attribution, including AI model/token usage.

Secure the AI pipeline, alongside our AI Lead. Ally's memory layer and multi-agent architecture handle sensitive, sometimes identifiable coaching conversation data for enterprise clients. You'll implement IAM policies and network controls that keep this data isolated and auditable, and work directly with Fede's team to make sure PII is protected before it reaches models or is persisted in memory.

Harden our delivery pipeline. Extend GitHub Actions with dependency/image scanning, secret hygiene, and OIDC workload identity (moving off long-lived keys) so merges to Cloud Run are checked without slowing the team down. Supply-chain hardening — SBOMs, artifact signing, Binary Authorization — is a natural next step as this matures, not a day-one expectation.

Own compliance operations day to day. We're SOC2 Type II certified with active enterprise relationships that carry recurring GDPR and security-questionnaire obligations — this is work our clients directly care about, and it's currently split across our leadership team's time. You'll take it on as your own: Vanta evidence collection and monitoring, coordinating vulnerability scans and any penetration tests, and drafting technical security questionnaire responses, with Alex's support on prioritization.

Partner, don't gatekeep. Work alongside our Platform engineering pod so developers can ship and own their own service infrastructure — patterns, modules, reviews, health checks — without you becoming a bottleneck. You're the security and reliability authority; you're not the only person who touches infrastructure day to day.

Who You Are

- A DevOps native. You write code to create infrastructure, not clicks in a console. You believe in immutable infrastructure.
- Security-first, by default. You think in least privilege, and know how to lock down a GCP project without blocking developers.

- A pragmatic scaler. You match the tool to the vigente problem — you won't reach for Kubernetes because it's the "serious" answer when Cloud Run solves it.
- Calm under fire. You can debug a production incident — a database lock, a failed auth handshake,



a bad deploy — without losing your head, and you document it afterward so it doesn't recur.

- Cost-aware. You treat cloud spend as a real signal, not an afterthought someone deals with at the end of the quarter.

Requirements

- 3–5 years of DevOps / SRE / SecOps experience, ideally including some ownership of production infrastructure (not just contributing to someone else's).

- Solid, hands-on GCP experience: IAM, networking, Cloud Run, Cloud Build/Cloud Storage.
- Practical Terraform experience in real environments — writing and applying modules/configs, not just reading them.
- Solid Docker/containerization experience.

- Fluent in Bash, plus comfort in Python and/or Ruby.
- Experience building/maintaining CI/CD pipelines (GitHub Actions or equivalent), including basic security gates (scanning, secrets, OIDC).
- Some exposure to SOC2 or a similar compliance framework.

- Comfortable communicating clearly about risk and trade-offs, and proactively flagging when something is outside your depth rather than guessing.
- Conversational English.

Nice to Haves

- Experience deploying to or securing Vertex AI / GCP AI workloads (model endpoints, GPU quotas, agent frameworks, RAG data paths).
- Direct SOC2 or ISO 27001 audit experience.
- Rails hosting/production experience.

- Software supply-chain security experience (SBOM, SLSA provenance, artifact signing, Binary Authorization).
- FinOps experience: cost attribution, budgets/alerts, rightsizing, or tracking AI model/token spend specifically.
- Multi-region/data-residency architecture experience (e.g., GeoDNS-based routing for regional compliance requirements).

Compensation $55,000 - $85,000/yr base

Why AceUp

- Real ownership, real mentorship. You'll run production infrastructure from day one, with Alex and Fede actively reviewing your biggest decisions and backing you up — not sink-or-swim.
- Modern problems, not legacy maintenance. You'll work on live AI infrastructure — Vertex AI, a multi-agent architecture, an evolving memory system — not a decade-old monolith with no roadmap.
- Fully remote, LATAM-friendly. Contractor engagement designed around where you work, not where we are.
- Compensation: Competitive, based on experience — happy to discuss specifics as part of the process.

How to Apply Send a resume and short intro to [email protected]. Tell us about a real production infrastructure or security problem you found and fixed — we care more about how you think through a problem than about matching every line of this list.

AceUp is proud to be an equal opportunity employer, seeking to create a welcoming and diverse environment. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status.

📌 Cloud/Infra Engineer (Infrastructure & Security) (Argentina)
🏢 AceUp
📍 Argentina

Postulate a este anuncio

Muestra tus habilidades a la empresa, rellenar el formulario y deja un toque personal en la carta, ayudará el reclutador en la elección del candidato.

Suscribete a esta alerta:

Recibe por email las nuevas ofertas de trabajo para: cloud/infra engineer (infrastructure & security) (argentina) / argentina

Suscribete a esta alerta:

Recibe por email las nuevas ofertas de trabajo para: cloud/infra engineer (infrastructure & security) (argentina) / argentina