feat(ruag): submit AI Engineer C5I, and record the Kdo Cy package

RUAG C5I - AI Engineer C5I (Thun, app ID 18027): SUBMITTED 2026-08-27.
Evidence Fit 74/100, fit class Stretch, title-capability hard gate FAIL
(R1 build/operate the AI-LLM platform and R2 in-house LLM/retrieval are
Adjacent, not Direct) - all knowingly accepted under the user's explicit
Phase 0 override. Consumes the cohort's sole Stretch slot: cohort is now
6/10, Stretch 1/1.

Critique ran twice. Round 1 scored the documents 85/100 and raised three
Tier 1 items; Round 2, after the fixes, scores 93/100 with truth and
provenance 24/25 and zero Tier 1 findings. Evidence Fit did not move and
was not allowed to: PP-3 is a personal project and cannot convert an
Adjacent title-capability into a Direct one.

Documents (.tex is the deliverable; PDFs are gitignored):
- resume 2pp/13 bullets, letter 1pp/295 words, both validators PASS
- headline is now the canonical title "Staff Data, Analytics & AI
  Engineer", which puts the req's own word above the fold
- PP-3 added as a Projekte section - the only current Linux/hardening
  evidence, since BS-6 ended Dec 2022
- the letter names the AI-platform gap in one sentence, then connects
  SW-5 to C5I's stated DevSecOps model
- "governte" -> "governance-konforme"; JD term coverage 18/22 -> 22/22
  claimable, with all six gap terms still correctly absent

Two defects found and fixed that the first critique missed:
- the resume never loaded babel, so a German document was hyphenated
  with English patterns (Hal-bleiterfertigung, Tran-skription). Fixed
  with babel[ngerman] plus a Transkription exception; this also cleared
  an overfull box. Check this on every future German package -
  resume_template.tex likely has the same omission.
- IBM AI Engineering had no primary-source record. Certificate read
  directly (IBM via Coursera, 4 Jun 2020, verify 3ZBZFVAL6A34), recorded
  as entry #8; it also proves PyTorch, now evidence: certification.

Also included: the submitted Kdo Cy DevOps Engineer III package, the
Capgemini omit rule promoted into config.md, BW-1 canonicalized in
experience_bundeswehr.md, and a scout.py comment correcting the
telenorgroup slug from "near-empty" to a claimed board serving stale
phantom listings that DEMO_TITLES would not catch.

Compensation, PSP/project eligibility and role level were never resolved
before sending and are now live screening topics.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JMcHCsTKWvVzqyLChF5ckk
This commit is contained in:
2026-08-27 23:20:17 +02:00
co-authored by Claude Opus 5
parent 93b0fc5b76
commit a0f844c143
21 changed files with 2305 additions and 80 deletions
+11
View File
@@ -157,6 +157,8 @@ _Update this section when starting/finishing a JD._
| Session | Status | Next Command |
|---------|--------|-------------|
| RUAG C5I - **AI Engineer C5I**, **Thun** (application ID 18027) | **SUBMITTED 2026-08-27** via jobs.ruag.ch (portal only; email and post refused). Evidence Fit **74/100**, fit class **Stretch**, hard gate **FAIL** (R1 and R2, the two title-defining responsibilities, are Adjacent not Direct), Document Quality **93/100** after a full critique-and-fix round (85 pre-edit), truth and provenance 24/25, **0 Tier 1 findings at Round 2**, channel **Weak/cold**. Submitted: German CV **2 pages, 13 bullets** + German motivation letter **1 page, 295 words**; both validators PASS, 0 boxes, text-order and visual QA clean, submission PDFs MD5-verified before sending. **Cohort evidence-first-2026-01 is now 6/10 and the sole Stretch slot is CONSUMED (Core 3/7, Adjacent 2/2, Stretch 1/1)** - any further application must clear Core or Adjacent on its own merits. Positioning is his canonical title **Staff Data, Analytics & AI Engineer**, carried by `BS-1` production ML-inference integration, `BS-6` Linux/Ansible, `SW-3`/`SW-7`/`SW-2` current Kubernetes and data-product work, `PP-3` current self-hosted Linux and hardening, `SW-5` DevSecOps tied to C5I's stated operating model, and the canonical `BW-1` officer career. The letter **names the AI-platform gap in one sentence** and pivots to the operations/platform side. **Honest gaps that travel with it:** no AI/LLM platform built or operated, no compute/GPU cluster, no RAG/retrieval implementation, no formal LLM evaluation; ML/AI-framework depth is certification-context only. **Compensation, PSP/project eligibility and role level were NEVER resolved before sending, so all three are now live screening topics rather than pre-cleared ones.****Marco Heinzen's published direct line (+41 79 568 14 96) was never used** - this went in as a pure cold submit, the sixth consecutive one. **If rejected, that is NOT a signal to drop RUAG:** five other RUAG C5I reqs sit in the scout log, and **Senior DevOps Engineer C5I** and **Data Lakehouse / Senior Data Platform Engineer** are both already shortlisted and are **materially better fits than this one**, sitting on the lane where his evidence is Direct rather than Adjacent. | Await response. Optional but still worthwhile: call **Marco Heinzen** about technical scope and level, and **Frank Haugwitz** about compensation and PSP/project eligibility. Do not react to a single outcome with positioning changes (`application_strategy.md` §38/§74). |
| Schweizer Armee - **Kommando Cyber (Kdo Cy)**, DevOps Engineer III (Data Platform), **Zimmerwald** (Ref JRQ$540-19848) | **SUBMITTED 2026-08-27.** Evidence Fit **79/Core**, hard gate **PASS**, Document Quality **92/100**, channel **Weak**. Submitted package: German 2-page CV with **15 bullets** and 1-page motivation letter with **300 body words**; validators PASS, 0 boxes, text order and visual QA clean. Canonical **BW-1** records the six-year Bundeswehr officer career and anchors the letter's military/public-service motivation. User explicitly accepted the critique's remaining BS-1 wording issue (*„ohne manuellen Eingriff“*) as good enough and submitted unchanged. Honest gaps remain physical datacenter work, GPGPU, ClickHouse and named Pull-GitOps practice. Cohort evidence-first-2026-01 is now **5/10, Core 3/7**. | Await response; optional post-submit call to Marcel Matthey-Doret about Lohnklasse, Engineer-III level and development path. |
| Citadel Securities — Platform Engineer, Research Platform Engineering, **Zürich** (also NY/Miami) | **SUBMITTED 2026-08-26.** Cohort slot: **Adjacent 2/2** (cohort now 4/10). ⚠️ **KEY FINDING — the application form's preferred-work-location selector offered NO Zurich**, despite the JD saying "Miami, Zurich or New York" and the site's own Zurich filter returning this req. Careers site is operated by **Citadel Enterprise Americas LLC**; the apply flow is likely US-entity, or the Zurich seat is closed while the posting stands. **This partly supersedes the working-model risk** — if no Zurich seat is reachable through that form, hybrid-vs-onsite is moot and the application may sit against a US req, a hard NO on relocation. **Rule for any future Citadel application: check the form's location selector BEFORE building a package** — the posting's stated locations and the site filter both proved unreliable. User applied with low expectation; cold channel, evergreen standing req. 2pp resume (13 bullets) + 1pp CL (270 words), both validator **PASS, 0 warnings**; JD term coverage 51%→68% after Tier 1 fixes. Critique **STALE by design** (86/100 pre-edit; user chose to submit as-is over re-critiquing; est. ~91 post-edit, never quote as a score). **Cohort entry and decision-log entry deliberately NOT written — no confirmed send date.** Commands ready in the session file. **The working-model question is still open and travels with the application:** Evidence Fit **71/100 (Adjacent, mid-band; revised down from 74)**, qualifications gate PASS but **a practical constraint is UNRESOLVED**, which `critique_framework.md` treats as a NO-GO trigger. **The JD is silent on hybrid vs onsite (0 grep matches), and Ken Griffin is on record that Citadel returned to the office 5 days a week and calls it his most important leadership decision.** If that holds for Zurich, it means ~22.5h daily commuting from Bern or relocating — breaking the Bern-based / 23 day hybrid bar. Only contrary evidence is a stale 2022 anonymous Fishbowl post about Operations. **Must be asked, not researched** — same class as the SBB K band. Practical constraints scored 5/5 in Phase 0 on an unexamined assumption; corrected to 2/5. **Zero Gaps among the 7 minimum quals**, and all five preferred technologies (Kafka, Kubernetes, Spark, Airflow, distributed DBs) are Direct — **the strongest raw stack alignment in the log**. Title-defining function **splits**: R2 (ingestion/transformation/storage/lifecycle of large datasets) is Direct and describes SW-1/SW-7 exactly; **R1 (design and build the research platform itself) is Adjacent** — the Aker BP authoring-vs-building shape again, and unwritable-around under Scope Discipline. **Classification caveat:** `application_strategy.md`'s "a defining responsibility is only Adjacent → Stretch" would strictly class this Stretch; recorded Adjacent per the Aker BP precedent. Both cohort slots free either way. Gaps: platform authoring at firm scale, no professional quant/finance (now partly mitigated by new **PP-1/PP-2**), SDKs (0 evidence), low-latency/HFT (0 evidence — thesis throughput figure is explicitly barred by `thesis_limits`). **Go is NOT a gap** — Q3 is disjunctive and Python satisfies it. **$175350k in the posting is a US/NY pay-transparency disclosure, NOT the Zurich number — must be asked.** Channel **Weak/cold** — would be the 5th consecutive cold application, in an office visibly staffed from Google and ETH (platform research head Costas Bekas; Nicolai Meinshausen leads principal research). Cover letter: **YES** if it proceeds — the PP-1 domain story is the main differentiator and needs prose. | **Ask Citadel Securities recruiting whether the Zurich seat is hybrid or 5-day onsite BEFORE building the package.** If 5-day onsite → likely NO-GO on the Bern constraint. If hybrid 23 days → resume Phase 2 (plan is written and budget PASSes at 1114 bullets; two open items: Vizrt VZ-1 C++/distributed bullet, and adding a Projects section for PP-1) |
| SBB — Data Engineer (m/w/d), Asset Management Infrastrukturanlagen, **Bern** (Job ID 103755) | **SUBMITTED 2026-08-25.** Cohort slot: **Core (evidence-first-2026-01)**. 2pp English resume (13 bullets, validator PASS) + critique: **Document Quality 92/100** (90 at critique, +2 after Edit 1), hard gate PASS, no Tier 1 truth findings, **no outstanding fixes**. No cover letter — SBB waives it. Evidence Fit **79/100 (Core, lower end)**, hard gate **PASS** — the title-defining capability (build/operate cloud data pipelines and governed data products) is Direct and current, unlike the AWS FDE NO-GO. Best practical fit in the log: **Bern-based, German-language, no relocation, EU citizen + B permit**. Real strength cluster for the *vorausschauende Wartung* purpose — Bosch fab sensor/process data, ELK/Kafka anomaly detection, containerized ML inference, plus the condition-monitoring thesis. **Two open risks, both level/comp not fit:** (1) **Anforderungsniveau K** is a capped GAV band and the figures are not public — must be asked, not researched; (2) the seat reads **lateral or below** current Staff + Component Owner scope (same shape as the declined BKW). Named gaps: Snowflake, dbt, Argo Workflows, Helm, Power BI, Spring Boot, Angular — all non-canonical, survivable only because the JD prefixes the stack list with "z. B.". **Cover letter: NO — SBB explicitly waives it.** Channel: posting names **Andri Wienandts, People Leader, +41 79 364 62 53** — the first published warm entry point in the entire log. **The comp question was NOT resolved before submitting**, so the K band is now a live screening topic rather than a pre-cleared one; the same applies to Kidz Care childcare support (up to 90% of Betreuungskosten but scaled on *gross household* income, so realistically far less at this level — bracket table is intranet-only). | Prep an interview brief before any screening call: (1) Anforderungsniveau K band figures, (2) design/architecture scope vs current Staff + Component Owner level, (3) Kidz Care actual rate at this band. Named gaps to have honest answers for: Snowflake, dbt, Argo Workflows, Helm, Power BI |
| AWS (AWS EMEA SARL, Switzerland Branch) — Senior Forward Deployed Engineer, Zürich (job 10504263) | **CLOSED — NO-GO 2026-08-18** at the Phase 0 gate. Evidence Fit **69/100** (Adjacent). Minimum-qual gate passed (all 4 Basic Quals Direct) but the *title-defining* capability — customer embedding — is a Gap that `claims.json` globally forbids claiming, and R2 multi-agent/retrieval is a second Gap. User declined: **69 is below the fit bar worth spending a package on.** Consistent with revealed behaviour — every application actually submitted scored **77.589**; nothing below 75 has ever been sent. **No cohort slot consumed (Adjacent stays 1/2).** Phase 0 analysis retained in the session file for reuse if a better-fitting AWS req appears. | Done — no package built |
@@ -189,6 +191,15 @@ _See `config.md` for user-specific corrections. Add verified errors here as you
| Date | Correction | Files fixed |
|------|-----------|-------------|
| 2026-08-27 | **A German-language resume was being typeset with English hyphenation patterns, and had been for every German package built from this template.** The RUAG resume loaded `lmodern` but **never `babel`** - the cover letter did (`\usepackage[ngerman]{babel}`), the resume did not. The compiled PDF broke words as `Hal-bleiterfertigung`, `Tran-skription`, `automa-tisierte` and `Foun-dation`: all wrong in German, and exactly the kind of thing a native-German Swiss reader notices without being able to name. It survived an earlier full visual QA because nothing *looks* broken - the lines are justified and the page is clean. Adding `\usepackage[ngerman]{babel}` produced correct breaks (`Halb-leiterfertigung`, `automati-sierte`) and **also cleared an overfull box** introduced when the headline grew. ngerman still breaks `Transkription` after `Tran`, so `\hyphenation{Trans-krip-ti-on}` was added. **Rule: any German-language document must load `babel[ngerman]`, and hyphenation must be checked in the compiled PDF, not assumed from a clean box count.** `resume_template.tex` should be checked for the same omission. | RUAG resume (fixed); `resume_template.tex` (OPEN) |
| 2026-08-27 | **`IBM AI Engineering` was on resumes for months with no primary-source record, and `PyTorch` was under-recorded as a result.** The `/critique` flagged it as the only line a canonical preflight could not confirm: the other three certifications sit in `thiessen_certifications.md` with issuer, date and certificate number, while this one existed only in `bundle_ml_ai_engineer.md`. The user supplied the PDF (`C:\myCloud\Bewerbungsunterlagen\Zeugnisse\Zertifikate\cert_IBM_AI_Engineering.pdf`) and it was read directly: **IBM via Coursera, 4 Jun 2020**, no expiry, verify code `3ZBZFVAL6A34`, six courses, name on the certificate `Dennis Thiessen` (sz variant, as on ITIL and iSAQB). Recorded as entry **#8**. It also proves **PyTorch**, which `claims.json` had as `coursework-or-personal-unverified`; upgraded to `evidence: certification` with `output` unchanged at `certification-context-only`. The certificate is explicitly **non-credit** and confers no grade or degree - never present it as an academic qualification. **Same shape as the Ansible/Linux/Bosch-promotion gaps: the claim was true, the KB simply had no record of it.** | `thiessen_certifications.md` (entry 8); `claims.json` (PyTorch evidence) |
| 2026-08-27 | **`claims.json` had no Bosch promotion date, so a Swisscom-style title line was unwritable from the canonical file.** Asked to render Bosch like Swisscom ("Senior Data Engineer, Data Analysis (Beförderung xy)"), the canonical file offered only a combined `official_title` "Engineer / Senior Engineer, Data Analysis" with **no `title_history` and no date** - while SWISSCOM has a full `title_history`. The data existed one layer down: `experience_bosch.md` records it LinkedIn-confirmed as Data Engineer **Feb 2020 - Jan 2021** and **Senior** Data Engineer **Jan 2021 - Dez 2022**. Added to `claims.json` as `title_history`, with `display_title` set to the user's own preferred wording **"Senior Data Engineer, Data Analysis"** and `official_title` left untouched as the formal Zeugnis string. **Systemic lesson, the same shape as the Ansible/Linux gaps: `claims.json` is the declared highest authority but is not always the most complete file - when it is silent, check the `experience/` files before telling the user something is unwritable.** Edit note: the file uses compact inline JSON and CRLF; a `json.dumps(indent=2)` rewrite reformats all ~700 lines. Patch it as text. | `claims.json` (BOSCH title_history, display_title); RUAG resume |
| 2026-08-27 | **Vizrt shown as "DevOps Engineer" alone, on user instruction.** Canonical `official_title` is **"Test Automation Engineer"**; `display_title` is "Test Automation / DevOps Engineer". The user asked to drop "Test Automation" for the RUAG C5I package. Bullet content (CI/CD quality gates, Python backend for distributed transcoding) supports the DevOps framing and the user is the authority on his own role - but **this is the one title on that document that will not match a Zeugnis word-for-word**, so flag it rather than silently propagate it. Not written into `claims.json`: it is a per-package display choice, not a canonical correction. | RUAG resume (session file records the flag) |
| 2026-08-27 | **A finished package had no reviewable PDF, and the only PDF that existed was a stale pre-fix build.** The RUAG C5I resume was recorded as complete, but the previous session had compiled only into a scratch folder (`.tmp_ruag_ai_resume/`), so `output/RUAG_AI_Engineer_C5I/` held just the `.tex`. The user could not approve what he could not open. Worse, that scratch folder still contained a **pre-correction PDF that included Capgemini**, named with the deliverable's stem - one grab away from being submitted. The folder also held a stale 3-page text extraction, which is why the prior session's "both pages visually inspected" claim had been made against a different document than the final one. **Rule: compile the PDF into the application's own `output/` folder** (as the Kdo Cy package does), and never leave a superseded PDF beside a deliverable. "Output .tex only" means the .tex is the source of truth, **not** that the user should be handed nothing to look at. | RUAG output folder (PDF added, stale temp folder deleted); `config.md` (Output Rules) |
| 2026-08-27 | **Capgemini reappeared in a generated resume, breaking a standing omit preference.** The RUAG C5I draft carried `Capgemini Deutschland GmbH, Nov. 2014 - Mai 2015` as a compact chronology entry. The user does **not** want Capgemini on any document (six months only; short-stay impression in Germany). A corpus check found it was the **only** generated `.tex` under `output/` containing the name, so this was a one-off regression, not a systemic drift. **Root cause: the preference had no first-class home.** It lived in memory and in a parenthetical inside the unrelated "12+ years" entry below, so a fresh model reading `CLAUDE.md` and `config.md` alone would not see it - `config.md` does not mention Capgemini at all. Recorded here as its own rule: **Capgemini is omitted from every resume, CV and cover letter. The resulting Nov. 2014 - Mai 2015 gap is intentional and must never be "fixed".** The visible chronology starts at Generali, Mai 2015 - which is also what the "over ten years" profile wording is measured against. | RUAG resume (fixed); this log (rule recorded) |
| 2026-08-27 | **The English resume template asserts "12+ years of production software experience" and that does not hold against `claims.json`.** Canonical `employment` starts at **Capgemini 2014-11** → ~11 years 9 months as of Aug 2026; and Capgemini is omitted from documents by standing user preference, so the *visible* record on any generated resume starts **Generali 2015-05** → ~11 years 3 months. Either reading falls short of twelve. Inherited unexamined into the Kdo Cy draft's opening sentence and caught at final review; corrected there to **"über zehn Jahren"**, which is true under both readings. **`resume_builder/templates/resume_template.tex` still carries the 12+ claim and will re-infect the next package.** Possible innocent explanation: officer service after the 2013 M.Eng. (he is a Universität-der-Bundeswehr graduate) may be counted and is not in `employment`**ask before editing the template**, and if it counts, record it in `claims.json` so the number has a source. Lesson: a number inherited from a template is still a claim and needs a canonical source like any other. | Kdo Cy resume (fixed); `resume_template.tex` (OPEN) |
| 2026-08-27 | **Linux administration was missing from `claims.json` entirely — the second infrastructure blind spot found the same day, and the more consequential one.** User-confirmed: at **Bosch (20202022) Linux servers carried everything** — ML platform hosts, Docker hosts, backend services, the Ansible control path — and he administered and automated them; he also **wrote Ansible extensions**, including a credential plugin pulling secrets from a password keystore with local caching to cut lookup volume (scalability/performance). Recorded as new claim **BS-6**. Separately, he has run a **self-hosted Debian server for ~10 years** — nginx, mail, Nextcloud, VPN, Docker services, Bitwarden — which he administers *and hardens*; recorded as **PP-3** with a PP-1-style forbidden list (never enterprise/production/multi-user, no uptime or scale figures, never employer work, never evidence of physical-datacenter experience). **Hardening evidence leans on the personal side — always say so.** **GitOps question resolved and the answer is NO:** playbooks were in Git but execution was **push-based from Jenkins/GitLab**, no reconciliation agent. The word stays `forbidden`; the substance is writable as *"versionskontrollierte Infrastrukturautomatisierung mit Ansible aus Git, ausgeführt über Jenkins-/GitLab-Pipelines"*. **Systemic lesson: the KB is data-engineering shaped and under-records infrastructure and operations work.** Two canonical gaps (Ansible, Linux) cost the Kdo Cy assessment ~15 points and produced an initial NO-GO that reflected the KB, not the candidate. Before scoring any DevOps/platform/SRE-flavoured JD, ask about ops evidence explicitly rather than trusting `claims.json` to be complete. | `claims.json` (skills Linux administration + GitOps note, new claims BS-6 and PP-3) |
| 2026-08-27 | **Ansible was missing from `claims.json` entirely — a real, currently-relevant skill that could not legitimately be listed.** It already appeared in `experience_bosch.md` BS-1 bullet variants ("Docker, Kubernetes, Ansible"), but the canonical file had **zero** mentions in either `skills` or any claim, so by the evidence-first rule it was unwritable. User confirmed 2026-08-27 that Ansible work at Bosch (20202022) was **intensive** and went beyond the BS-1 ML-inference orchestration into configuration management and infrastructure automation. Added as `production-historical`, `output: allowed`, and BS-1's scope now records it. **This is genuine IaC evidence** alongside CloudFormation and it materially improves any DevOps/platform JD — it does **not** license Terraform, which stays unverified. **`GitOps` added as a separate, explicitly `forbidden` skill pending clarification:** the user described the Ansible work as GitOps, but Ansible is configuration management while GitOps is narrower (declarative desired state in Git, reconciled by an agent such as Argo CD or Flux). Until it is established whether playbooks lived in Git and were applied from there, and whether a reconciliation agent was involved, the word must not appear in any document. The Kdo Cy JD names **"Pull-GitOps"** explicitly, so that is the one audience guaranteed to probe the distinction. | `claims.json` (skills Ansible + GitOps, BS-1 scope) |
| 2026-08-21 | **The data-engineer bundle carried the SW-1 scope violation it was supposed to prevent.** `bundle_data_engineer.md` §S5's cover-letter opening hook read "*while simultaneously leading the migration of our legacy stack to a cloud-native AWS architecture*" — a full-ownership verb on a company-scale object, directly contradicting `claims.json` SW-1 `forbidden` **and** point 2 of the narrative thread three lines below it. Live trap for every future data-eng cover letter. Rewritten to the scoped form plus an inline scope warning. **Check the other four bundles for the same pattern.** | `bundle_data_engineer.md` (§S5 hook + new warning) |
| 2026-07-27 | **SW-1 was not solo.** Swisscom AWS migration was written as "sole technical lead" / "Led migration of legacy stack." Dennis was primary engineer for **his own domains'** pipelines and a contributor to the wider programme. | `experience_swisscom.md` (role line + all 3 bullet variants + overclaiming warning), `config.md` |
| 2026-07-27 | **Security Champion is 2025/2026 only, and is a team role — not an award.** Source files claimed "3 consecutive years (2023/242025/26)." User has now corrected this twice. **Default is OMIT** unless the JD explicitly requires security/DevSecOps. | `experience_swisscom.md` SW-5, `achievement_reframing_guide.md`, `skills_taxonomy.md` (3 rows) |