feat: rebuild evidence-first application workflow

This commit is contained in:
2026-07-27 17:56:15 +02:00
parent c24892f381
commit fe5f24704f
57 changed files with 3815 additions and 3555 deletions
@@ -1,5 +1,7 @@
# Experience: Software Engineer → IT Consultant — Generali Deutschland Informatik Services GmbH (GDIS)
## May 2015 June 2017 | Hamburg/Cologne, Germany
## May 2015 June 2017 | Hamburg, Germany
> **Location — corrected 2026-07-27 (user-confirmed).** Base was **Hamburg**. **Cologne and Vienna were stations during the international graduate traineeship**, several months each. The Zeugnis extraction's "Köln" is the source of the old error. Resume/CV line must read **Hamburg, Germany** — never "Cologne" or "Hamburg/Cologne". The Cologne/Vienna rotations are a minor international-mobility signal: omit from resume bullets, but usable in a cover letter or interview when the JD values international or travel-heavy delivery. See `[[feedback_generali_location]]`.
### Cross-Position Section
@@ -3,24 +3,26 @@
### Cross-Position Section
**Career arc framing:** Swisscom is Dennis's current and most senior role — a promotion from Senior to Staff (Engineer IV) in April 2025. This is the anchor position for all target role types. It demonstrates the full stack: owned pipelines, cloud migration, containerized delivery, security ownership, and stakeholder-facing data products. At a major national telco operating AWS-heavy infrastructure, this is the clearest signal for Staff/Senior Data Engineering, Data Platform, and ML Engineering roles.
**Career arc framing:** Swisscom is Dennis's current and most senior role — a promotion from Senior to Staff (Engineer IV) in April 2025. This is the anchor position for all target role types. It demonstrates owned pipeline components, scoped cloud-migration delivery, containerized operation and stakeholder-facing data products. The 2025/2026 Security Champion assignment is a secondary team role, not a core ownership claim.
**CL framing (for cover letters):** "My current role at Swisscom — Switzerland's largest telco — gives me end-to-end ownership of business-critical data pipelines at scale: from Oracle and Kafka ingestion through Teradata DWH to AWS cloud-native architecture. I've led the migration of legacy pipelines to serverless AWS services and own the full DevOps lifecycle including Kubernetes deployment, GitLab CI/CD, and on-call support."
**CL framing (for cover letters):** "At Swisscom I own business-critical pipeline components in the Fulfillment domain, from Oracle and Kafka ingestion through production support. I migrated my domains' pipelines onto the company's AWS platform and build governed data products within its wider Data Mesh, while contributing to the broader migration programme."
---
### Achievement SW-1: AWS Migration of Legacy ETL Stack
**Source:** thiessen_swisscom_zwischenzeugnis.md, thiessen_cv_master_profile.md
**User's role:** Primary owner / sole technical lead
**User's role:** Primary engineer for the migration of **his own domains'** pipelines; contributor to the wider company migration programme. **NOT a solo lead** — user-corrected 2026-07-27.
**Status:** Active / ongoing operational achievement
**Context:** Legacy ETL pipelines ran on Teradata and Oracle. Migration to AWS cloud-native stack reduces operational overhead, improves scalability, and positions the team for modern serverless workflows.
**Context:** Legacy ETL pipelines ran on Teradata and Oracle. Dennis implemented migration work for pipelines in his own domains using the company's AWS platform. No cost, scale or time-saving metric has been verified.
**Bullet variants:**
- **2L:** Migrated legacy Teradata/Oracle ETL pipelines to AWS cloud-native architecture (S3, Glue, Athena with Apache Iceberg, Redshift, Airflow, CloudFormation), reducing manual operational overhead and enabling scalable, serverless data processing for downstream analytics.
- **3L:** Led migration of legacy Teradata/Oracle ETL stack to a fully cloud-native AWS architecture using S3, Glue Jobs and Tables, Athena with Apache Iceberg (open table format), Redshift, Lambda, Step Functions, Airflow, and CloudFormation for IaC; reduced operational overhead, improved pipeline observability, and enabled scalable serverless processing — directly accelerating data availability for B2B stakeholder analytics.
- **1L:** Migrated legacy ETL stack to AWS (S3, Glue, Athena/Iceberg, Redshift, Airflow, CloudFormation) for scalable serverless data processing.
**Bullet variants:** (scope-corrected 2026-07-27 — object must be **his domains'** pipelines, never "the" company stack)
- **2L:** Migrated his domains' legacy Teradata/Oracle ETL pipelines to AWS cloud-native architecture (S3, Glue, Athena with Apache Iceberg, Redshift, Airflow, CloudFormation), reducing manual operational overhead and enabling scalable, serverless data processing for downstream analytics.
- **3L:** Migrated the Fulfillment and Product Analysis domains' legacy Teradata/Oracle ETL pipelines to a cloud-native AWS architecture using S3, Glue Jobs and Tables, Athena with Apache Iceberg (open table format), Redshift, Lambda, Step Functions, Airflow, and CloudFormation for IaC; reduced operational overhead, improved pipeline observability, and enabled scalable serverless processing — contributing to Swisscom's wider cloud migration programme.
- **1L:** Migrated his domains' ETL pipelines to AWS (S3, Glue, Athena/Iceberg, Redshift, Airflow, CloudFormation) for serverless processing.
**Overclaiming warning:** Do NOT write "Led migration of the legacy stack" or imply sole ownership of a company-wide migration. See CLAUDE.md Scope Discipline and `[[feedback_bigcorp_ownership_scope]]`.
**Key skills:** AWS, S3, Glue, Athena, Apache Iceberg, Redshift, Lambda, Step Functions, Airflow, CloudFormation, IaC, ETL migration, cloud-native architecture
**ATS keywords:** AWS, data pipeline migration, ETL, serverless, Airflow, Redshift, Glue, Athena, Apache Iceberg, CloudFormation, IaC
@@ -99,26 +101,29 @@
---
### Achievement SW-5: Security Champion — 3 Consecutive Years
### Achievement SW-5: Security Champion — 2025/2026 (team role, NOT an award)
**Source:** thiessen_swisscom_security_champion.md, thiessen_swisscom_zwischenzeugnis.md
**User's role:** Designated Security Champion (annually renewed)
**Status:** Active (2025/26 badge current)
**User's role:** Designated Security Champion — a mandatory team role (security point of contact), **not an award or honor**
**Status:** Active **2025/2026 only**
**Context:** Swisscom's Security Champion program requires 100h of structured training covering Cloud Security, DevSecOps, Security by Design, and Risk Management, plus a 40-question assessment (>80% passing grade). Dennis has held this role for 3 consecutive years.
> **CORRECTED 2026-07-27 (user-confirmed, second time).** This was previously written as "3 consecutive years (2023/242025/26)" — that is **wrong**. Dennis holds the badge for **2025/2026 only**. It is a rotating team role, not a distinction. See `config.md` KB Corrections and `[[feedback_security_champion]]`.
>
> **Default action: OMIT from resume and CV.** Include only when the JD explicitly requires security or DevSecOps experience. Never list under Awards/Honors.
**Bullet variants:**
- **2L:** Named Swisscom Security Champion for 3 consecutive years (2023/242025/26), owning security compliance, risk monitoring and deviation tracking for the team's pipelines; completed 100h annual DevSecOps training with >80% assessment score.
- **3L:** Designated as Security Champion for Swisscom's Data Lake team for 3 consecutive years (2023/24, 2024/25, 2025/26) — responsible for security compliance in development and operation, risk monitoring, and deviation reporting; fulfilled annual 100h structured training across Cloud Security, DevSecOps, Security by Design, and Security Risk Management, passing a 40-question comprehensive assessment with >80% score each year.
- **1L:** Swisscom Security Champion for 3 consecutive years (20232026) — DevSecOps, risk monitoring, 100h training + assessment.
**Context:** Swisscom's Security Champion program requires 100h of structured training covering Cloud Security, DevSecOps, Security by Design, and Risk Management, plus a 40-question assessment (>80% passing grade).
**Bullet variants:** (use ONLY if the JD explicitly asks for security/DevSecOps)
- **2L:** Serve as Security Champion for the team (2025/2026), covering security compliance, risk monitoring and deviation tracking for the team's pipelines; completed 100h DevSecOps training with >80% assessment score.
- **1L:** Team Security Champion (2025/2026) — DevSecOps, risk monitoring, 100h training + assessment.
**Key skills:** DevSecOps, security compliance, risk management, security awareness, Security by Design
**ATS keywords:** DevSecOps, security champion, security compliance, risk management, cloud security
**Reframing notes:**
- Data Platform/Infra: HIGH relevance — embed security in infrastructure angle
- Staff/Senior DE: include as supporting signal for senior-level ownership breadth
- Data Platform/Infra: LOW by default; include only when the JD explicitly requires security or DevSecOps exposure
- Staff/Senior DE: LOW by default; do not use as a generic seniority signal
- Analytics Engineer: LOW — de-emphasize or omit unless JD asks for security awareness
- ML/AI: include for AI-adjacent roles where model security/compliance is relevant
- ML/AI: include only when the JD explicitly asks for security/compliance; this is not responsible-AI ownership
---
@@ -146,22 +151,22 @@
### Achievement SW-7: Data Mesh, Data Products & Metadata Management (AWS) — Foundation for Agentic AI
**Source:** User-verified current work (2026), thiessen_cv_master_profile.md (AWS stack)
**User's role:** Primary developer / current Staff-level focus area
**User's role:** Builds and models governed data products and onboards sources within Swisscom's company-wide Data Mesh; does not own or architect the shared company-wide mesh.
**Status:** Active / ongoing (current emphasis)
**Context:** Current Staff-level work building decentralized **Data Mesh** architecture, reusable **data products**, and active **metadata management** on AWS (Glue, Athena, CloudFormation, AWS CLI, CI/CD deployments). This is the governed, discoverable data foundation that downstream AI and **agentic workflows** depend on — enabling "AI speak-to-data" / grounded retrieval over enterprise data. Directly maps to agentic reference-architecture and MCP-based tool/data-access requirements.
**Context:** Current Staff-level work builds reusable governed **data products**, active metadata and source onboarding within Swisscom's shared Data Mesh on AWS (Glue, Athena, CloudFormation, AWS CLI, CI/CD). These products can support downstream analytics and AI use cases. Do not convert this into ownership of agent architecture, MCP tooling or the company-wide platform.
**Bullet variants:**
- **2L:** Built decentralized Data Mesh and reusable data products with active metadata management on AWS (Glue, Athena, CloudFormation, CI/CD) — the governed, discoverable data foundation that downstream AI and agentic workflows query directly.
- **3L:** Architected decentralized Data Mesh with reusable, governed data products and active metadata management on AWS (Glue, Athena, CloudFormation, AWS CLI, automated CI/CD) — establishing the discoverable, well-described data foundation that downstream AI and agentic workflows depend on for grounded, "speak-to-data" retrieval over enterprise sources.
- **1L:** Built AWS Data Mesh, data products and metadata management — the governed data foundation for downstream AI/agentic workflows.
- **2L:** Build governed data products with active metadata management within Swisscom's company-wide Data Mesh on AWS (Glue, Athena, CloudFormation), supporting discoverable data access for analytics and AI use cases.
- **3L:** Model and build governed data products, onboard source systems and maintain active metadata within Swisscom's company-wide Data Mesh on AWS (Glue, Athena, CloudFormation and CI/CD), giving downstream teams discoverable, well-described data without claiming ownership of the shared platform.
- **1L:** Build governed data products and metadata within Swisscom's company-wide AWS Data Mesh.
**Key skills:** Data Mesh, data products, metadata management, data catalog, data governance, AWS, Glue, Athena, CloudFormation, AWS CLI, CI/CD, agentic data foundation, grounded retrieval
**ATS keywords:** Data Mesh, data products, metadata management, AWS, Glue, Athena, CloudFormation, CI/CD, data governance, grounded retrieval, agentic AI foundation
**Reframing notes:**
- ML/AI (agentic): HIGH — lead bridge to "reference architecture for agentic systems" + "grounded retrieval / MCP tool-data access"; frame data layer as what agents query
- ML/AI: MED — evidence for data readiness and grounded enterprise data, not agent architecture or retrieval ownership
- Data Platform/Infra: HIGH — Data Mesh + metadata + AWS IaC is core platform signal
- Staff/Senior DE: HIGH — decentralized architecture ownership at scale
- Staff/Senior DE: HIGH — governed data-product delivery within a company-wide architecture
- Analytics Engineer: MED — data products enable self-serve analytics
---
@@ -193,7 +198,7 @@
| Component Owner / Fulfillment ETL | SW-2 | HIGH | HIGH | MED | HIGH |
| Kubernetes + GitLab CI/CD | SW-3 | HIGH | MED | HIGH | HIGH |
| B2B Data Products + Automation | SW-4 | MED | HIGH | MED | MED |
| Security Champion | SW-5 | MED | LOW | MED | HIGH |
| Security Champion | SW-5 | LOW | LOW | LOW | LOW |
| PySpark | SW-6 | MED | LOW | MED | MED |
| Data Mesh / Data Products / Metadata (agentic foundation) | SW-7 | HIGH | MED | HIGH | HIGH |
| Domain-Grounded LLM Agents | SW-8 | MED | LOW | HIGH | MED |