feat: rebuild evidence-first application workflow

This commit is contained in:
2026-07-27 17:56:15 +02:00
parent c24892f381
commit fe5f24704f
57 changed files with 3815 additions and 3555 deletions
@@ -8,7 +8,7 @@
## S1: Role Profile & Priority Matrix
**Positioning:** Dennis's data platform and infrastructure experience is woven throughout his career rather than being a dedicated "platform engineer" role — but the evidence is substantive: Kubernetes ownership at two employers, AWS migration with CloudFormation/IaC, GitLab CI/CD automation, Docker containerization of ML workloads, observability stack (ELK + Grafana + Prometheus), and 3 consecutive years as Swisscom Security Champion (DevSecOps). Position as "Data Engineer with strong platform and infrastructure ownership" rather than a dedicated Platform/SRE/DevOps role.
**Positioning:** Dennis's platform evidence sits inside data-engineering roles rather than a dedicated Platform/SRE title: Kubernetes delivery at Swisscom and Bosch, scoped AWS migration work with CloudFormation, GitLab CI/CD, Dockerized ML inference and an observability proof of concept. Position as a data engineer with production-platform depth, not as a dedicated SRE, developer-platform or Terraform engineer.
**Note on Tier 3:** This bundle is viable but slightly less natural than Tier 1/2. The gap is: Dennis doesn't have a dedicated platform engineering title, and his infrastructure work is in service of data pipelines rather than standalone infrastructure. Frame accordingly — emphasize that his platform skills are production-proven, not academic.
@@ -39,7 +39,7 @@
- "Kubernetes-based containerized pipeline deployment"
- "AWS IaC (CloudFormation)" — infrastructure-as-code signal
- "AWS migration" — hands-on cloud platform experience
- "DevSecOps / Security Champion" — security-aware platform engineer
- Security Champion is not a default positioning theme; use the 2025/2026 team role only when the JD explicitly requires security exposure
- "ELK + Grafana + Prometheus observability stack"
**Tone:** Infrastructure-minded engineer who thinks about reliability, observability, and security — not just data throughput. Platform thinking embedded in data work.
@@ -56,11 +56,11 @@
| ID | Default Framing | This Role's Framing | Key Metric / Signal |
|----|----------------|--------------------|--------------------|
| SW-3 | K8s + GitLab | **Lead bullet** — "Deployed and operated Python data applications on Kubernetes with GitLab CI/CD; drove infrastructure automation in agile DevOps team" | K8s + CI/CD ownership = core platform signal |
| SW-1 | AWS migration | "Migrated legacy ETL stack to cloud-native AWS (S3, Glue, Athena/Iceberg, Redshift, Airflow, CloudFormation) — full IaC stack provisioned via CloudFormation" | CloudFormation/IaC + full AWS service breadth |
| SW-1 | AWS migration | "Migrated pipelines in his owned domains from legacy Teradata/Oracle processing onto Swisscom's AWS platform (Glue, Athena/Iceberg, Redshift, Airflow, CloudFormation)" | Scoped migration delivery plus AWS breadth |
| SW-2 | Component Owner | "Owned Fulfillment ETL pipelines (Oracle/Kafka → Teradata) — platform reliability, Data Governance compliance, 2nd/3rd-level support and on-call duty" | Platform SLA + on-call = reliability engineer signal |
| BS-1 | ML inference | "Containerized and orchestrated ML inference (Docker, K8s, Ansible) into 24/7 semiconductor production — zero-downtime constrained deployment" | Production-grade containerization under hardest constraints |
| BS-4 | ELK PoC | "Designed and delivered observability stack: ELK + Kafka, Grafana dashboards, Prometheus metrics, Loki log aggregation — full monitoring suite for manufacturing infrastructure" | Full observability stack implementation |
| SW-5 | Security Champion | "Swisscom Security Champion ×3 (20232026) — DevSecOps ownership, security compliance, risk monitoring and deviation tracking for Data Lake team" | Security ownership in platform context |
| SW-5 | Security Champion | "2025/2026 team Security Champion; include only if the JD explicitly requires security or DevSecOps exposure" | Secondary team-role evidence, not ownership or certification |
| BS-2 | Data services | "Built multi-language data services (Python/Java/C#) over OracleDB and Hadoop/ImpalaSQL — platform-layer data access for semiconductor analysis teams" | Enterprise DB + Hadoop infrastructure |
| BS-3 | App Owner | "Application Owner for semiconductor analytics platform — SLOs, reliability, vendor management, on-call coverage" | Platform SLA ownership |
| FC-1 | CI/CD initiative | "Independently introduced Jenkins CI/CD pipeline with quality gates at Fraunhofer CML — first build automation adopted by the research team" | Initiative: built CI/CD from zero |
@@ -112,7 +112,7 @@ Kubernetes, Docker, AWS (S3 · Glue · Athena · Redshift · CloudFormation), Ka
1. **Production Kubernetes** — SW-3 + BS-1: K8s at two employers, in different contexts (data apps at Swisscom, ML inference at Bosch). Cross-employer K8s ownership is a strong signal.
2. **Full AWS platform stack** — SW-1: Not just using one AWS service — migrating an entire ETL infrastructure to AWS with CloudFormation/IaC shows platform-level thinking.
3. **Observability initiative** — BS-4: Self-initiated ELK + Prometheus + Grafana PoC shows platform engineer mindset (monitoring is not optional).
4. **Security ownership** — SW-5: Security Champion ×3 = DevSecOps embedded in platform work, not an afterthought.
4. **Operational accountability** — use Component/Application Owner evidence. Security Champion is optional and never a substitute for production ownership.
**"Why them" angle to research:**
- What is their cloud stack? If AWS-heavy → your SAA cert + migration experience is directly relevant