Compare commits

...
2 Commits
Author SHA1 Message Date
dennisthiessenandClaude Opus 5 a0f844c143 feat(ruag): submit AI Engineer C5I, and record the Kdo Cy package
RUAG C5I - AI Engineer C5I (Thun, app ID 18027): SUBMITTED 2026-08-27.
Evidence Fit 74/100, fit class Stretch, title-capability hard gate FAIL
(R1 build/operate the AI-LLM platform and R2 in-house LLM/retrieval are
Adjacent, not Direct) - all knowingly accepted under the user's explicit
Phase 0 override. Consumes the cohort's sole Stretch slot: cohort is now
6/10, Stretch 1/1.

Critique ran twice. Round 1 scored the documents 85/100 and raised three
Tier 1 items; Round 2, after the fixes, scores 93/100 with truth and
provenance 24/25 and zero Tier 1 findings. Evidence Fit did not move and
was not allowed to: PP-3 is a personal project and cannot convert an
Adjacent title-capability into a Direct one.

Documents (.tex is the deliverable; PDFs are gitignored):
- resume 2pp/13 bullets, letter 1pp/295 words, both validators PASS
- headline is now the canonical title "Staff Data, Analytics & AI
  Engineer", which puts the req's own word above the fold
- PP-3 added as a Projekte section - the only current Linux/hardening
  evidence, since BS-6 ended Dec 2022
- the letter names the AI-platform gap in one sentence, then connects
  SW-5 to C5I's stated DevSecOps model
- "governte" -> "governance-konforme"; JD term coverage 18/22 -> 22/22
  claimable, with all six gap terms still correctly absent

Two defects found and fixed that the first critique missed:
- the resume never loaded babel, so a German document was hyphenated
  with English patterns (Hal-bleiterfertigung, Tran-skription). Fixed
  with babel[ngerman] plus a Transkription exception; this also cleared
  an overfull box. Check this on every future German package -
  resume_template.tex likely has the same omission.
- IBM AI Engineering had no primary-source record. Certificate read
  directly (IBM via Coursera, 4 Jun 2020, verify 3ZBZFVAL6A34), recorded
  as entry #8; it also proves PyTorch, now evidence: certification.

Also included: the submitted Kdo Cy DevOps Engineer III package, the
Capgemini omit rule promoted into config.md, BW-1 canonicalized in
experience_bundeswehr.md, and a scout.py comment correcting the
telenorgroup slug from "near-empty" to a claimed board serving stale
phantom listings that DEMO_TITLES would not catch.

Compensation, PSP/project eligibility and role level were never resolved
before sending and are now live screening topics.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JMcHCsTKWvVzqyLChF5ckk
2026-08-27 23:20:17 +02:00
dennisthiessenandClaude Opus 5 93b0fc5b76 chore(akerbp): record rejection, cold channel and slot stays consumed
Rejected 2026-08-27, no interview, ~28 days after submission. Recorded
in all four places that track an outcome: cohort state, decision log,
the Active Sessions row and the session file's status block.

The cohort slot is not freed. A rejection consumes an attempt the same
way a submission does, so the Adjacent count stays 2/2 and the cohort
stays 4/10 - unlike the Google FDE III and AWS FDE no-gos, which were
declined before a package existed.

Recorded as rejected_no_interview on the evidence: nothing in the log
shows any contact after submission. Recruiter-vs-hiring-manager
disposition is a tracked cohort variable, so this is one edit away from
being corrected if a screen did happen.

The package was validator PASS with no Tier 1 truth findings and the
follow-up email to Per Olav Marthinsen was never actioned, making this a
pure cold submit. A cold-channel no-interview rejection does not
implicate document quality on its own. That is now 2 of 4 cohort
applications rejected without interview, both cold, which fits the
channel thesis already in the log - and application_strategy.md forbids
reacting to a single rejection, so no positioning or targeting changed.

The Norway lane is explicitly not closed. NATO JWC Stavanger is still
live and strong Norwegian employers remain in scope; both the row and
the decision note say so, because with Aker BP closed the earlier
Equinor note ("lane now reduced to the open Aker BP application") would
otherwise read as an implied closure.

Submission date left inconsistent on purpose: the contemporaneous
records say 2026-07-29, the retrospective ones 2026-07-30. Both now
carry a note pointing at the other rather than one being overwritten.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JMcHCsTKWvVzqyLChF5ckk
2026-08-27 14:45:09 +02:00
22 changed files with 2316 additions and 90 deletions
+2
View File
@@ -157,6 +157,8 @@ _Update this section when starting/finishing a JD._
| Session | Status | Next Command | | Session | Status | Next Command |
|---------|--------|-------------| |---------|--------|-------------|
| RUAG C5I - **AI Engineer C5I**, **Thun** (application ID 18027) | **SUBMITTED 2026-08-27** via jobs.ruag.ch (portal only). Evidence Fit **74/100**, fit class **Stretch**, hard gate **FAIL** (R1/R2, the title-defining responsibilities, are Adjacent not Direct), Document Quality **93/100** after a critique-and-fix round, channel **Weak/cold**. German CV 2 pages/13 bullets + motivation letter 1 page/295 words; validators PASS, 0 boxes, visual QA clean. **Cohort now 6/10 and the sole Stretch slot is CONSUMED (Stretch 1/1).** Positioning is his canonical title Staff Data, Analytics & AI Engineer; `PP-3` carries current Linux/hardening evidence and `SW-5` ties DevSecOps to C5I's stated model. The letter names the AI-platform gap in one sentence. Honest gaps: no AI/LLM platform, no compute/GPU cluster, no RAG/retrieval, ML/AI frameworks certification-context only. **Compensation, PSP/project eligibility and level were never resolved and are now live screening topics.** Marco Heinzen's published direct line was never used. **If rejected, do not drop RUAG** - Senior DevOps Engineer C5I and Data Lakehouse / Senior Data Platform Engineer are shortlisted and fit better. | Await response; optional calls to Marco Heinzen (scope/level) and Frank Haugwitz (comp/PSP). |
| Schweizer Armee - **Kommando Cyber (Kdo Cy)**, DevOps Engineer III (Data Platform), **Zimmerwald** (Ref JRQ$540-19848) | **SUBMITTED 2026-08-27.** Evidence Fit **79/Core**, hard gate **PASS**, Document Quality **92/100**, channel **Weak**. German 2-page CV plus 1-page motivation letter; validators PASS, 0 boxes, visual QA clean. BW-1 surfaces the six-year Bundeswehr officer career. User explicitly accepted the critique's remaining BS-1 wording issue (*„ohne manuellen Eingriff“*) as good enough and submitted unchanged. Cohort evidence-first-2026-01 is now 5/10, Core 3/7. | Await response; optional post-submit call to Marcel Matthey-Doret about Lohnklasse, Engineer-III level and development path. |
| Google - Software Engineer III, Business Home, Zurich (req 93922217108087494) | **CLOSED - NOT PROCEEDING 2026-07-28** (submitted 2026-07-27; Core, Evidence Fit 89/100, Document Quality 94/100; no interview). Rapid early-screen disposition; known risks were Mid-level versus current Staff scope, data/platform versus product-SWE positioning, preferred algorithms/accessibility gaps, and a cold channel. | Done - cohort rejection recorded; do not treat this outcome alone as a document-quality failure | | Google - Software Engineer III, Business Home, Zurich (req 93922217108087494) | **CLOSED - NOT PROCEEDING 2026-07-28** (submitted 2026-07-27; Core, Evidence Fit 89/100, Document Quality 94/100; no interview). Rapid early-screen disposition; known risks were Mid-level versus current Staff scope, data/platform versus product-SWE positioning, preferred algorithms/accessibility gaps, and a cold channel. | Done - cohort rejection recorded; do not treat this outcome alone as a document-quality failure |
| Microsoft — Principal Forward Deployed Engineer, SWE (German Speaking), Zürich (req 200043897) | **SUBMITTED 2026-07-27** (84.2/100 Pass 2; finalized 2-page resume + 1-page cover letter). Strong native-German, Staff progression, production ownership and enterprise-data-readiness case; honest gaps remain in end-to-end LLM delivery, Azure AI and strategic-account FDE experience. | Done — await response | | Microsoft — Principal Forward Deployed Engineer, SWE (German Speaking), Zürich (req 200043897) | **SUBMITTED 2026-07-27** (84.2/100 Pass 2; finalized 2-page resume + 1-page cover letter). Strong native-German, Staff progression, production ownership and enterprise-data-readiness case; honest gaps remain in end-to-end LLM delivery, Azure AI and strategic-account FDE experience. | Done — await response |
| BIS Basel — Senior Data & Analytics Engineer, AI (jr100429, 3-yr term) | **SENT 2026-07-10** (80.5/100; deadline 2026-07-24; hybrid Basel, English-working intl org). Critique flags LLM-depth probe (integration/config vs. ownership) as the screening risk — prep honest answer before any call | Prep interview brief when screening lands | | BIS Basel — Senior Data & Analytics Engineer, AI (jr100429, 3-yr term) | **SENT 2026-07-10** (80.5/100; deadline 2026-07-24; hybrid Basel, English-working intl org). Critique flags LLM-depth probe (integration/config vs. ownership) as the screening risk — prep honest answer before any call | Prep interview brief when screening lands |
+12 -1
View File
@@ -157,12 +157,14 @@ _Update this section when starting/finishing a JD._
| Session | Status | Next Command | | Session | Status | Next Command |
|---------|--------|-------------| |---------|--------|-------------|
| RUAG C5I - **AI Engineer C5I**, **Thun** (application ID 18027) | **SUBMITTED 2026-08-27** via jobs.ruag.ch (portal only; email and post refused). Evidence Fit **74/100**, fit class **Stretch**, hard gate **FAIL** (R1 and R2, the two title-defining responsibilities, are Adjacent not Direct), Document Quality **93/100** after a full critique-and-fix round (85 pre-edit), truth and provenance 24/25, **0 Tier 1 findings at Round 2**, channel **Weak/cold**. Submitted: German CV **2 pages, 13 bullets** + German motivation letter **1 page, 295 words**; both validators PASS, 0 boxes, text-order and visual QA clean, submission PDFs MD5-verified before sending. **Cohort evidence-first-2026-01 is now 6/10 and the sole Stretch slot is CONSUMED (Core 3/7, Adjacent 2/2, Stretch 1/1)** - any further application must clear Core or Adjacent on its own merits. Positioning is his canonical title **Staff Data, Analytics & AI Engineer**, carried by `BS-1` production ML-inference integration, `BS-6` Linux/Ansible, `SW-3`/`SW-7`/`SW-2` current Kubernetes and data-product work, `PP-3` current self-hosted Linux and hardening, `SW-5` DevSecOps tied to C5I's stated operating model, and the canonical `BW-1` officer career. The letter **names the AI-platform gap in one sentence** and pivots to the operations/platform side. **Honest gaps that travel with it:** no AI/LLM platform built or operated, no compute/GPU cluster, no RAG/retrieval implementation, no formal LLM evaluation; ML/AI-framework depth is certification-context only. **Compensation, PSP/project eligibility and role level were NEVER resolved before sending, so all three are now live screening topics rather than pre-cleared ones.****Marco Heinzen's published direct line (+41 79 568 14 96) was never used** - this went in as a pure cold submit, the sixth consecutive one. **If rejected, that is NOT a signal to drop RUAG:** five other RUAG C5I reqs sit in the scout log, and **Senior DevOps Engineer C5I** and **Data Lakehouse / Senior Data Platform Engineer** are both already shortlisted and are **materially better fits than this one**, sitting on the lane where his evidence is Direct rather than Adjacent. | Await response. Optional but still worthwhile: call **Marco Heinzen** about technical scope and level, and **Frank Haugwitz** about compensation and PSP/project eligibility. Do not react to a single outcome with positioning changes (`application_strategy.md` §38/§74). |
| Schweizer Armee - **Kommando Cyber (Kdo Cy)**, DevOps Engineer III (Data Platform), **Zimmerwald** (Ref JRQ$540-19848) | **SUBMITTED 2026-08-27.** Evidence Fit **79/Core**, hard gate **PASS**, Document Quality **92/100**, channel **Weak**. Submitted package: German 2-page CV with **15 bullets** and 1-page motivation letter with **300 body words**; validators PASS, 0 boxes, text order and visual QA clean. Canonical **BW-1** records the six-year Bundeswehr officer career and anchors the letter's military/public-service motivation. User explicitly accepted the critique's remaining BS-1 wording issue (*„ohne manuellen Eingriff“*) as good enough and submitted unchanged. Honest gaps remain physical datacenter work, GPGPU, ClickHouse and named Pull-GitOps practice. Cohort evidence-first-2026-01 is now **5/10, Core 3/7**. | Await response; optional post-submit call to Marcel Matthey-Doret about Lohnklasse, Engineer-III level and development path. |
| Citadel Securities — Platform Engineer, Research Platform Engineering, **Zürich** (also NY/Miami) | **SUBMITTED 2026-08-26.** Cohort slot: **Adjacent 2/2** (cohort now 4/10). ⚠️ **KEY FINDING — the application form's preferred-work-location selector offered NO Zurich**, despite the JD saying "Miami, Zurich or New York" and the site's own Zurich filter returning this req. Careers site is operated by **Citadel Enterprise Americas LLC**; the apply flow is likely US-entity, or the Zurich seat is closed while the posting stands. **This partly supersedes the working-model risk** — if no Zurich seat is reachable through that form, hybrid-vs-onsite is moot and the application may sit against a US req, a hard NO on relocation. **Rule for any future Citadel application: check the form's location selector BEFORE building a package** — the posting's stated locations and the site filter both proved unreliable. User applied with low expectation; cold channel, evergreen standing req. 2pp resume (13 bullets) + 1pp CL (270 words), both validator **PASS, 0 warnings**; JD term coverage 51%→68% after Tier 1 fixes. Critique **STALE by design** (86/100 pre-edit; user chose to submit as-is over re-critiquing; est. ~91 post-edit, never quote as a score). **Cohort entry and decision-log entry deliberately NOT written — no confirmed send date.** Commands ready in the session file. **The working-model question is still open and travels with the application:** Evidence Fit **71/100 (Adjacent, mid-band; revised down from 74)**, qualifications gate PASS but **a practical constraint is UNRESOLVED**, which `critique_framework.md` treats as a NO-GO trigger. **The JD is silent on hybrid vs onsite (0 grep matches), and Ken Griffin is on record that Citadel returned to the office 5 days a week and calls it his most important leadership decision.** If that holds for Zurich, it means ~22.5h daily commuting from Bern or relocating — breaking the Bern-based / 23 day hybrid bar. Only contrary evidence is a stale 2022 anonymous Fishbowl post about Operations. **Must be asked, not researched** — same class as the SBB K band. Practical constraints scored 5/5 in Phase 0 on an unexamined assumption; corrected to 2/5. **Zero Gaps among the 7 minimum quals**, and all five preferred technologies (Kafka, Kubernetes, Spark, Airflow, distributed DBs) are Direct — **the strongest raw stack alignment in the log**. Title-defining function **splits**: R2 (ingestion/transformation/storage/lifecycle of large datasets) is Direct and describes SW-1/SW-7 exactly; **R1 (design and build the research platform itself) is Adjacent** — the Aker BP authoring-vs-building shape again, and unwritable-around under Scope Discipline. **Classification caveat:** `application_strategy.md`'s "a defining responsibility is only Adjacent → Stretch" would strictly class this Stretch; recorded Adjacent per the Aker BP precedent. Both cohort slots free either way. Gaps: platform authoring at firm scale, no professional quant/finance (now partly mitigated by new **PP-1/PP-2**), SDKs (0 evidence), low-latency/HFT (0 evidence — thesis throughput figure is explicitly barred by `thesis_limits`). **Go is NOT a gap** — Q3 is disjunctive and Python satisfies it. **$175350k in the posting is a US/NY pay-transparency disclosure, NOT the Zurich number — must be asked.** Channel **Weak/cold** — would be the 5th consecutive cold application, in an office visibly staffed from Google and ETH (platform research head Costas Bekas; Nicolai Meinshausen leads principal research). Cover letter: **YES** if it proceeds — the PP-1 domain story is the main differentiator and needs prose. | **Ask Citadel Securities recruiting whether the Zurich seat is hybrid or 5-day onsite BEFORE building the package.** If 5-day onsite → likely NO-GO on the Bern constraint. If hybrid 23 days → resume Phase 2 (plan is written and budget PASSes at 1114 bullets; two open items: Vizrt VZ-1 C++/distributed bullet, and adding a Projects section for PP-1) | | Citadel Securities — Platform Engineer, Research Platform Engineering, **Zürich** (also NY/Miami) | **SUBMITTED 2026-08-26.** Cohort slot: **Adjacent 2/2** (cohort now 4/10). ⚠️ **KEY FINDING — the application form's preferred-work-location selector offered NO Zurich**, despite the JD saying "Miami, Zurich or New York" and the site's own Zurich filter returning this req. Careers site is operated by **Citadel Enterprise Americas LLC**; the apply flow is likely US-entity, or the Zurich seat is closed while the posting stands. **This partly supersedes the working-model risk** — if no Zurich seat is reachable through that form, hybrid-vs-onsite is moot and the application may sit against a US req, a hard NO on relocation. **Rule for any future Citadel application: check the form's location selector BEFORE building a package** — the posting's stated locations and the site filter both proved unreliable. User applied with low expectation; cold channel, evergreen standing req. 2pp resume (13 bullets) + 1pp CL (270 words), both validator **PASS, 0 warnings**; JD term coverage 51%→68% after Tier 1 fixes. Critique **STALE by design** (86/100 pre-edit; user chose to submit as-is over re-critiquing; est. ~91 post-edit, never quote as a score). **Cohort entry and decision-log entry deliberately NOT written — no confirmed send date.** Commands ready in the session file. **The working-model question is still open and travels with the application:** Evidence Fit **71/100 (Adjacent, mid-band; revised down from 74)**, qualifications gate PASS but **a practical constraint is UNRESOLVED**, which `critique_framework.md` treats as a NO-GO trigger. **The JD is silent on hybrid vs onsite (0 grep matches), and Ken Griffin is on record that Citadel returned to the office 5 days a week and calls it his most important leadership decision.** If that holds for Zurich, it means ~22.5h daily commuting from Bern or relocating — breaking the Bern-based / 23 day hybrid bar. Only contrary evidence is a stale 2022 anonymous Fishbowl post about Operations. **Must be asked, not researched** — same class as the SBB K band. Practical constraints scored 5/5 in Phase 0 on an unexamined assumption; corrected to 2/5. **Zero Gaps among the 7 minimum quals**, and all five preferred technologies (Kafka, Kubernetes, Spark, Airflow, distributed DBs) are Direct — **the strongest raw stack alignment in the log**. Title-defining function **splits**: R2 (ingestion/transformation/storage/lifecycle of large datasets) is Direct and describes SW-1/SW-7 exactly; **R1 (design and build the research platform itself) is Adjacent** — the Aker BP authoring-vs-building shape again, and unwritable-around under Scope Discipline. **Classification caveat:** `application_strategy.md`'s "a defining responsibility is only Adjacent → Stretch" would strictly class this Stretch; recorded Adjacent per the Aker BP precedent. Both cohort slots free either way. Gaps: platform authoring at firm scale, no professional quant/finance (now partly mitigated by new **PP-1/PP-2**), SDKs (0 evidence), low-latency/HFT (0 evidence — thesis throughput figure is explicitly barred by `thesis_limits`). **Go is NOT a gap** — Q3 is disjunctive and Python satisfies it. **$175350k in the posting is a US/NY pay-transparency disclosure, NOT the Zurich number — must be asked.** Channel **Weak/cold** — would be the 5th consecutive cold application, in an office visibly staffed from Google and ETH (platform research head Costas Bekas; Nicolai Meinshausen leads principal research). Cover letter: **YES** if it proceeds — the PP-1 domain story is the main differentiator and needs prose. | **Ask Citadel Securities recruiting whether the Zurich seat is hybrid or 5-day onsite BEFORE building the package.** If 5-day onsite → likely NO-GO on the Bern constraint. If hybrid 23 days → resume Phase 2 (plan is written and budget PASSes at 1114 bullets; two open items: Vizrt VZ-1 C++/distributed bullet, and adding a Projects section for PP-1) |
| SBB — Data Engineer (m/w/d), Asset Management Infrastrukturanlagen, **Bern** (Job ID 103755) | **SUBMITTED 2026-08-25.** Cohort slot: **Core (evidence-first-2026-01)**. 2pp English resume (13 bullets, validator PASS) + critique: **Document Quality 92/100** (90 at critique, +2 after Edit 1), hard gate PASS, no Tier 1 truth findings, **no outstanding fixes**. No cover letter — SBB waives it. Evidence Fit **79/100 (Core, lower end)**, hard gate **PASS** — the title-defining capability (build/operate cloud data pipelines and governed data products) is Direct and current, unlike the AWS FDE NO-GO. Best practical fit in the log: **Bern-based, German-language, no relocation, EU citizen + B permit**. Real strength cluster for the *vorausschauende Wartung* purpose — Bosch fab sensor/process data, ELK/Kafka anomaly detection, containerized ML inference, plus the condition-monitoring thesis. **Two open risks, both level/comp not fit:** (1) **Anforderungsniveau K** is a capped GAV band and the figures are not public — must be asked, not researched; (2) the seat reads **lateral or below** current Staff + Component Owner scope (same shape as the declined BKW). Named gaps: Snowflake, dbt, Argo Workflows, Helm, Power BI, Spring Boot, Angular — all non-canonical, survivable only because the JD prefixes the stack list with "z. B.". **Cover letter: NO — SBB explicitly waives it.** Channel: posting names **Andri Wienandts, People Leader, +41 79 364 62 53** — the first published warm entry point in the entire log. **The comp question was NOT resolved before submitting**, so the K band is now a live screening topic rather than a pre-cleared one; the same applies to Kidz Care childcare support (up to 90% of Betreuungskosten but scaled on *gross household* income, so realistically far less at this level — bracket table is intranet-only). | Prep an interview brief before any screening call: (1) Anforderungsniveau K band figures, (2) design/architecture scope vs current Staff + Component Owner level, (3) Kidz Care actual rate at this band. Named gaps to have honest answers for: Snowflake, dbt, Argo Workflows, Helm, Power BI | | SBB — Data Engineer (m/w/d), Asset Management Infrastrukturanlagen, **Bern** (Job ID 103755) | **SUBMITTED 2026-08-25.** Cohort slot: **Core (evidence-first-2026-01)**. 2pp English resume (13 bullets, validator PASS) + critique: **Document Quality 92/100** (90 at critique, +2 after Edit 1), hard gate PASS, no Tier 1 truth findings, **no outstanding fixes**. No cover letter — SBB waives it. Evidence Fit **79/100 (Core, lower end)**, hard gate **PASS** — the title-defining capability (build/operate cloud data pipelines and governed data products) is Direct and current, unlike the AWS FDE NO-GO. Best practical fit in the log: **Bern-based, German-language, no relocation, EU citizen + B permit**. Real strength cluster for the *vorausschauende Wartung* purpose — Bosch fab sensor/process data, ELK/Kafka anomaly detection, containerized ML inference, plus the condition-monitoring thesis. **Two open risks, both level/comp not fit:** (1) **Anforderungsniveau K** is a capped GAV band and the figures are not public — must be asked, not researched; (2) the seat reads **lateral or below** current Staff + Component Owner scope (same shape as the declined BKW). Named gaps: Snowflake, dbt, Argo Workflows, Helm, Power BI, Spring Boot, Angular — all non-canonical, survivable only because the JD prefixes the stack list with "z. B.". **Cover letter: NO — SBB explicitly waives it.** Channel: posting names **Andri Wienandts, People Leader, +41 79 364 62 53** — the first published warm entry point in the entire log. **The comp question was NOT resolved before submitting**, so the K band is now a live screening topic rather than a pre-cleared one; the same applies to Kidz Care childcare support (up to 90% of Betreuungskosten but scaled on *gross household* income, so realistically far less at this level — bracket table is intranet-only). | Prep an interview brief before any screening call: (1) Anforderungsniveau K band figures, (2) design/architecture scope vs current Staff + Component Owner level, (3) Kidz Care actual rate at this band. Named gaps to have honest answers for: Snowflake, dbt, Argo Workflows, Helm, Power BI |
| AWS (AWS EMEA SARL, Switzerland Branch) — Senior Forward Deployed Engineer, Zürich (job 10504263) | **CLOSED — NO-GO 2026-08-18** at the Phase 0 gate. Evidence Fit **69/100** (Adjacent). Minimum-qual gate passed (all 4 Basic Quals Direct) but the *title-defining* capability — customer embedding — is a Gap that `claims.json` globally forbids claiming, and R2 multi-agent/retrieval is a second Gap. User declined: **69 is below the fit bar worth spending a package on.** Consistent with revealed behaviour — every application actually submitted scored **77.589**; nothing below 75 has ever been sent. **No cohort slot consumed (Adjacent stays 1/2).** Phase 0 analysis retained in the session file for reuse if a better-fitting AWS req appears. | Done — no package built | | AWS (AWS EMEA SARL, Switzerland Branch) — Senior Forward Deployed Engineer, Zürich (job 10504263) | **CLOSED — NO-GO 2026-08-18** at the Phase 0 gate. Evidence Fit **69/100** (Adjacent). Minimum-qual gate passed (all 4 Basic Quals Direct) but the *title-defining* capability — customer embedding — is a Gap that `claims.json` globally forbids claiming, and R2 multi-agent/retrieval is a second Gap. User declined: **69 is below the fit bar worth spending a package on.** Consistent with revealed behaviour — every application actually submitted scored **77.589**; nothing below 75 has ever been sent. **No cohort slot consumed (Adjacent stays 1/2).** Phase 0 analysis retained in the session file for reuse if a better-fitting AWS req appears. | Done — no package built |
| Google — Forward Deployed Engineer III, Google Cloud GTM (French, German), Zürich (req 78350205438567110) | **CLOSED — NOT PROCEEDING 2026-08-18.** Phase 0 was done (Evidence Fit 67/100, hard gate PASS) but user declined to proceed after **two Google rejections** (Merchant Data Science, Business Home): the bar is now that a Google req must fit *very* well to be worth a third attempt, and this one was Adjacent with an agent-orchestration Gap. **Frees the Adjacent cohort slot (back to 1/2).** Phase 1 never started. | Done — do not reopen without a materially stronger Google req | | Google — Forward Deployed Engineer III, Google Cloud GTM (French, German), Zürich (req 78350205438567110) | **CLOSED — NOT PROCEEDING 2026-08-18.** Phase 0 was done (Evidence Fit 67/100, hard gate PASS) but user declined to proceed after **two Google rejections** (Merchant Data Science, Business Home): the bar is now that a Google req must fit *very* well to be worth a third attempt, and this one was Adjacent with an agent-orchestration Gap. **Frees the Adjacent cohort slot (back to 1/2).** Phase 1 never started. | Done — do not reopen without a materially stronger Google req |
| SDU Center for Energy Informatics, Odense DK — PhD, Theme 2 Predictive Maintenance & Asset Management of Smart Energy Networks (job 4159) | **CLOSED — NOT PROCEEDING 2026-08-18.** Enquiry email to Prof. Bo Nørregaard Jørgensen (sent 2026-08-02) went unanswered for 16 days; user dismissed the idea. Genuine thesis fit (vibration condition monitoring, RBR+ANN hybrid) but the blockers were never the documents — 2 letters of recommendation 13 years out of academia, and DKK 37,075/mo ≈ CHF 56k against a 180k bar. Deadline was 2026-08-20. | Done — no further action | | SDU Center for Energy Informatics, Odense DK — PhD, Theme 2 Predictive Maintenance & Asset Management of Smart Energy Networks (job 4159) | **CLOSED — NOT PROCEEDING 2026-08-18.** Enquiry email to Prof. Bo Nørregaard Jørgensen (sent 2026-08-02) went unanswered for 16 days; user dismissed the idea. Genuine thesis fit (vibration condition monitoring, RBR+ANN hybrid) but the blockers were never the documents — 2 letters of recommendation 13 years out of academia, and DKK 37,075/mo ≈ CHF 56k against a 180k bar. Deadline was 2026-08-20. | Done — no further action |
| Aker BP ASA — Data Product Architect, AI-ready Data Products (FINN 469067315) | **SUBMITTED 2026-07-30** (ahead of the 2026-08-02 deadline; Adjacent, **Evidence Fit 79/100**, Document Quality 93/100, hard gate PASS, Channel Weak; Stavanger/Oslo/Trondheim, English working language, no Norwegian and no clearance required, EEA work rights). 2pp resume + 1pp CL, both validator PASS. Honest practitioner framing: builds governed data products *inside* Swisscom's Data Mesh; role *authors* an enterprise framework — real level stretch, never fabricate authorship. **Atlassian Compass closed the catalogue-tool gap** (74→79). Remaining gaps: framework authorship, no energy domain, AWS vs their Microsoft/Cognite stack, **zero verified metrics**. | Done — await response; optional follow-up email to Per Olav Marthinsen | | Aker BP ASA — Data Product Architect, AI-ready Data Products (FINN 469067315) | **CLOSED — REJECTED 2026-08-27** (submitted 2026-07-30, ~28 days to disposition, no interview; the session file and cohort record record the submission as 2026-07-29 — a one-day inconsistency, never reconciled). Adjacent, **Evidence Fit 79/100**, Document Quality 93/100, hard gate PASS, **Channel Weak/cold** — the optional follow-up email to Per Olav Marthinsen was left unsent, so this went in as a pure cold submit. Stavanger/Oslo/Trondheim, English working language, no Norwegian and no clearance required, EEA work rights. 2pp resume + 1pp CL, both validator PASS, no Tier 1 truth findings — **a cold-channel no-interview rejection does not implicate document quality on its own** (same disposition class as Microsoft ISE and Google Business Home). Honest practitioner framing: builds governed data products *inside* Swisscom's Data Mesh; role *authored* an enterprise framework — real level stretch, never fabricated authorship. **Atlassian Compass closed the catalogue-tool gap** (74→79). Standing gaps if a similar req appears: framework authorship, no energy domain, AWS vs their Microsoft/Cognite stack, **zero verified metrics**. **Cohort slot stays consumed** (evidence-first-2026-01, Adjacent 1/2 — a rejection does not free a slot; cohort remains 4/10). **The Norway lane stays OPEN and selective** — NATO JWC Stavanger is still live, and Equinor/Telenor and other strong Norwegian employers remain in scope per the user's standing instruction. Never frame this lane as closed. | Done — cohort rejection recorded; do not react to this single outcome with positioning changes (`application_strategy.md` §38/§74) |
| Google - Software Engineer III, Business Home, Zurich (req 93922217108087494) | **CLOSED - NOT PROCEEDING 2026-07-28** (submitted 2026-07-27; Core, Evidence Fit 89/100, Document Quality 94/100; no interview). Rapid early-screen disposition; known risks were Mid-level versus current Staff scope, data/platform versus product-SWE positioning, preferred algorithms/accessibility gaps, and a cold channel. | Done - cohort rejection recorded; do not treat this outcome alone as a document-quality failure | | Google - Software Engineer III, Business Home, Zurich (req 93922217108087494) | **CLOSED - NOT PROCEEDING 2026-07-28** (submitted 2026-07-27; Core, Evidence Fit 89/100, Document Quality 94/100; no interview). Rapid early-screen disposition; known risks were Mid-level versus current Staff scope, data/platform versus product-SWE positioning, preferred algorithms/accessibility gaps, and a cold channel. | Done - cohort rejection recorded; do not treat this outcome alone as a document-quality failure |
| Microsoft — Principal Forward Deployed Engineer, SWE (German Speaking), Zürich (req 200043897) | **SUBMITTED 2026-07-27** (84.2/100 Pass 2; finalized 2-page resume + 1-page cover letter). Strong native-German, Staff progression, production ownership and enterprise-data-readiness case; honest gaps remain in end-to-end LLM delivery, Azure AI and strategic-account FDE experience. | Done — await response | | Microsoft — Principal Forward Deployed Engineer, SWE (German Speaking), Zürich (req 200043897) | **SUBMITTED 2026-07-27** (84.2/100 Pass 2; finalized 2-page resume + 1-page cover letter). Strong native-German, Staff progression, production ownership and enterprise-data-readiness case; honest gaps remain in end-to-end LLM delivery, Azure AI and strategic-account FDE experience. | Done — await response |
| BIS Basel — Senior Data & Analytics Engineer, AI (jr100429, 3-yr term) | **SENT 2026-07-10** (80.5/100; deadline 2026-07-24; hybrid Basel, English-working intl org). Critique flags LLM-depth probe (integration/config vs. ownership) as the screening risk — prep honest answer before any call | Prep interview brief when screening lands | | BIS Basel — Senior Data & Analytics Engineer, AI (jr100429, 3-yr term) | **SENT 2026-07-10** (80.5/100; deadline 2026-07-24; hybrid Basel, English-working intl org). Critique flags LLM-depth probe (integration/config vs. ownership) as the screening risk — prep honest answer before any call | Prep interview brief when screening lands |
@@ -189,6 +191,15 @@ _See `config.md` for user-specific corrections. Add verified errors here as you
| Date | Correction | Files fixed | | Date | Correction | Files fixed |
|------|-----------|-------------| |------|-----------|-------------|
| 2026-08-27 | **A German-language resume was being typeset with English hyphenation patterns, and had been for every German package built from this template.** The RUAG resume loaded `lmodern` but **never `babel`** - the cover letter did (`\usepackage[ngerman]{babel}`), the resume did not. The compiled PDF broke words as `Hal-bleiterfertigung`, `Tran-skription`, `automa-tisierte` and `Foun-dation`: all wrong in German, and exactly the kind of thing a native-German Swiss reader notices without being able to name. It survived an earlier full visual QA because nothing *looks* broken - the lines are justified and the page is clean. Adding `\usepackage[ngerman]{babel}` produced correct breaks (`Halb-leiterfertigung`, `automati-sierte`) and **also cleared an overfull box** introduced when the headline grew. ngerman still breaks `Transkription` after `Tran`, so `\hyphenation{Trans-krip-ti-on}` was added. **Rule: any German-language document must load `babel[ngerman]`, and hyphenation must be checked in the compiled PDF, not assumed from a clean box count.** `resume_template.tex` should be checked for the same omission. | RUAG resume (fixed); `resume_template.tex` (OPEN) |
| 2026-08-27 | **`IBM AI Engineering` was on resumes for months with no primary-source record, and `PyTorch` was under-recorded as a result.** The `/critique` flagged it as the only line a canonical preflight could not confirm: the other three certifications sit in `thiessen_certifications.md` with issuer, date and certificate number, while this one existed only in `bundle_ml_ai_engineer.md`. The user supplied the PDF (`C:\myCloud\Bewerbungsunterlagen\Zeugnisse\Zertifikate\cert_IBM_AI_Engineering.pdf`) and it was read directly: **IBM via Coursera, 4 Jun 2020**, no expiry, verify code `3ZBZFVAL6A34`, six courses, name on the certificate `Dennis Thiessen` (sz variant, as on ITIL and iSAQB). Recorded as entry **#8**. It also proves **PyTorch**, which `claims.json` had as `coursework-or-personal-unverified`; upgraded to `evidence: certification` with `output` unchanged at `certification-context-only`. The certificate is explicitly **non-credit** and confers no grade or degree - never present it as an academic qualification. **Same shape as the Ansible/Linux/Bosch-promotion gaps: the claim was true, the KB simply had no record of it.** | `thiessen_certifications.md` (entry 8); `claims.json` (PyTorch evidence) |
| 2026-08-27 | **`claims.json` had no Bosch promotion date, so a Swisscom-style title line was unwritable from the canonical file.** Asked to render Bosch like Swisscom ("Senior Data Engineer, Data Analysis (Beförderung xy)"), the canonical file offered only a combined `official_title` "Engineer / Senior Engineer, Data Analysis" with **no `title_history` and no date** - while SWISSCOM has a full `title_history`. The data existed one layer down: `experience_bosch.md` records it LinkedIn-confirmed as Data Engineer **Feb 2020 - Jan 2021** and **Senior** Data Engineer **Jan 2021 - Dez 2022**. Added to `claims.json` as `title_history`, with `display_title` set to the user's own preferred wording **"Senior Data Engineer, Data Analysis"** and `official_title` left untouched as the formal Zeugnis string. **Systemic lesson, the same shape as the Ansible/Linux gaps: `claims.json` is the declared highest authority but is not always the most complete file - when it is silent, check the `experience/` files before telling the user something is unwritable.** Edit note: the file uses compact inline JSON and CRLF; a `json.dumps(indent=2)` rewrite reformats all ~700 lines. Patch it as text. | `claims.json` (BOSCH title_history, display_title); RUAG resume |
| 2026-08-27 | **Vizrt shown as "DevOps Engineer" alone, on user instruction.** Canonical `official_title` is **"Test Automation Engineer"**; `display_title` is "Test Automation / DevOps Engineer". The user asked to drop "Test Automation" for the RUAG C5I package. Bullet content (CI/CD quality gates, Python backend for distributed transcoding) supports the DevOps framing and the user is the authority on his own role - but **this is the one title on that document that will not match a Zeugnis word-for-word**, so flag it rather than silently propagate it. Not written into `claims.json`: it is a per-package display choice, not a canonical correction. | RUAG resume (session file records the flag) |
| 2026-08-27 | **A finished package had no reviewable PDF, and the only PDF that existed was a stale pre-fix build.** The RUAG C5I resume was recorded as complete, but the previous session had compiled only into a scratch folder (`.tmp_ruag_ai_resume/`), so `output/RUAG_AI_Engineer_C5I/` held just the `.tex`. The user could not approve what he could not open. Worse, that scratch folder still contained a **pre-correction PDF that included Capgemini**, named with the deliverable's stem - one grab away from being submitted. The folder also held a stale 3-page text extraction, which is why the prior session's "both pages visually inspected" claim had been made against a different document than the final one. **Rule: compile the PDF into the application's own `output/` folder** (as the Kdo Cy package does), and never leave a superseded PDF beside a deliverable. "Output .tex only" means the .tex is the source of truth, **not** that the user should be handed nothing to look at. | RUAG output folder (PDF added, stale temp folder deleted); `config.md` (Output Rules) |
| 2026-08-27 | **Capgemini reappeared in a generated resume, breaking a standing omit preference.** The RUAG C5I draft carried `Capgemini Deutschland GmbH, Nov. 2014 - Mai 2015` as a compact chronology entry. The user does **not** want Capgemini on any document (six months only; short-stay impression in Germany). A corpus check found it was the **only** generated `.tex` under `output/` containing the name, so this was a one-off regression, not a systemic drift. **Root cause: the preference had no first-class home.** It lived in memory and in a parenthetical inside the unrelated "12+ years" entry below, so a fresh model reading `CLAUDE.md` and `config.md` alone would not see it - `config.md` does not mention Capgemini at all. Recorded here as its own rule: **Capgemini is omitted from every resume, CV and cover letter. The resulting Nov. 2014 - Mai 2015 gap is intentional and must never be "fixed".** The visible chronology starts at Generali, Mai 2015 - which is also what the "over ten years" profile wording is measured against. | RUAG resume (fixed); this log (rule recorded) |
| 2026-08-27 | **The English resume template asserts "12+ years of production software experience" and that does not hold against `claims.json`.** Canonical `employment` starts at **Capgemini 2014-11** → ~11 years 9 months as of Aug 2026; and Capgemini is omitted from documents by standing user preference, so the *visible* record on any generated resume starts **Generali 2015-05** → ~11 years 3 months. Either reading falls short of twelve. Inherited unexamined into the Kdo Cy draft's opening sentence and caught at final review; corrected there to **"über zehn Jahren"**, which is true under both readings. **`resume_builder/templates/resume_template.tex` still carries the 12+ claim and will re-infect the next package.** Possible innocent explanation: officer service after the 2013 M.Eng. (he is a Universität-der-Bundeswehr graduate) may be counted and is not in `employment`**ask before editing the template**, and if it counts, record it in `claims.json` so the number has a source. Lesson: a number inherited from a template is still a claim and needs a canonical source like any other. | Kdo Cy resume (fixed); `resume_template.tex` (OPEN) |
| 2026-08-27 | **Linux administration was missing from `claims.json` entirely — the second infrastructure blind spot found the same day, and the more consequential one.** User-confirmed: at **Bosch (20202022) Linux servers carried everything** — ML platform hosts, Docker hosts, backend services, the Ansible control path — and he administered and automated them; he also **wrote Ansible extensions**, including a credential plugin pulling secrets from a password keystore with local caching to cut lookup volume (scalability/performance). Recorded as new claim **BS-6**. Separately, he has run a **self-hosted Debian server for ~10 years** — nginx, mail, Nextcloud, VPN, Docker services, Bitwarden — which he administers *and hardens*; recorded as **PP-3** with a PP-1-style forbidden list (never enterprise/production/multi-user, no uptime or scale figures, never employer work, never evidence of physical-datacenter experience). **Hardening evidence leans on the personal side — always say so.** **GitOps question resolved and the answer is NO:** playbooks were in Git but execution was **push-based from Jenkins/GitLab**, no reconciliation agent. The word stays `forbidden`; the substance is writable as *"versionskontrollierte Infrastrukturautomatisierung mit Ansible aus Git, ausgeführt über Jenkins-/GitLab-Pipelines"*. **Systemic lesson: the KB is data-engineering shaped and under-records infrastructure and operations work.** Two canonical gaps (Ansible, Linux) cost the Kdo Cy assessment ~15 points and produced an initial NO-GO that reflected the KB, not the candidate. Before scoring any DevOps/platform/SRE-flavoured JD, ask about ops evidence explicitly rather than trusting `claims.json` to be complete. | `claims.json` (skills Linux administration + GitOps note, new claims BS-6 and PP-3) |
| 2026-08-27 | **Ansible was missing from `claims.json` entirely — a real, currently-relevant skill that could not legitimately be listed.** It already appeared in `experience_bosch.md` BS-1 bullet variants ("Docker, Kubernetes, Ansible"), but the canonical file had **zero** mentions in either `skills` or any claim, so by the evidence-first rule it was unwritable. User confirmed 2026-08-27 that Ansible work at Bosch (20202022) was **intensive** and went beyond the BS-1 ML-inference orchestration into configuration management and infrastructure automation. Added as `production-historical`, `output: allowed`, and BS-1's scope now records it. **This is genuine IaC evidence** alongside CloudFormation and it materially improves any DevOps/platform JD — it does **not** license Terraform, which stays unverified. **`GitOps` added as a separate, explicitly `forbidden` skill pending clarification:** the user described the Ansible work as GitOps, but Ansible is configuration management while GitOps is narrower (declarative desired state in Git, reconciled by an agent such as Argo CD or Flux). Until it is established whether playbooks lived in Git and were applied from there, and whether a reconciliation agent was involved, the word must not appear in any document. The Kdo Cy JD names **"Pull-GitOps"** explicitly, so that is the one audience guaranteed to probe the distinction. | `claims.json` (skills Ansible + GitOps, BS-1 scope) |
| 2026-08-21 | **The data-engineer bundle carried the SW-1 scope violation it was supposed to prevent.** `bundle_data_engineer.md` §S5's cover-letter opening hook read "*while simultaneously leading the migration of our legacy stack to a cloud-native AWS architecture*" — a full-ownership verb on a company-scale object, directly contradicting `claims.json` SW-1 `forbidden` **and** point 2 of the narrative thread three lines below it. Live trap for every future data-eng cover letter. Rewritten to the scoped form plus an inline scope warning. **Check the other four bundles for the same pattern.** | `bundle_data_engineer.md` (§S5 hook + new warning) | | 2026-08-21 | **The data-engineer bundle carried the SW-1 scope violation it was supposed to prevent.** `bundle_data_engineer.md` §S5's cover-letter opening hook read "*while simultaneously leading the migration of our legacy stack to a cloud-native AWS architecture*" — a full-ownership verb on a company-scale object, directly contradicting `claims.json` SW-1 `forbidden` **and** point 2 of the narrative thread three lines below it. Live trap for every future data-eng cover letter. Rewritten to the scoped form plus an inline scope warning. **Check the other four bundles for the same pattern.** | `bundle_data_engineer.md` (§S5 hook + new warning) |
| 2026-07-27 | **SW-1 was not solo.** Swisscom AWS migration was written as "sole technical lead" / "Led migration of legacy stack." Dennis was primary engineer for **his own domains'** pipelines and a contributor to the wider programme. | `experience_swisscom.md` (role line + all 3 bullet variants + overclaiming warning), `config.md` | | 2026-07-27 | **SW-1 was not solo.** Swisscom AWS migration was written as "sole technical lead" / "Led migration of legacy stack." Dennis was primary engineer for **his own domains'** pipelines and a contributor to the wider programme. | `experience_swisscom.md` (role line + all 3 bullet variants + overclaiming warning), `config.md` |
| 2026-07-27 | **Security Champion is 2025/2026 only, and is a team role — not an award.** Source files claimed "3 consecutive years (2023/242025/26)." User has now corrected this twice. **Default is OMIT** unless the JD explicitly requires security/DevSecOps. | `experience_swisscom.md` SW-5, `achievement_reframing_guide.md`, `skills_taxonomy.md` (3 rows) | | 2026-07-27 | **Security Champion is 2025/2026 only, and is a team role — not an award.** Source files claimed "3 consecutive years (2023/242025/26)." User has now corrected this twice. **Default is OMIT** unless the JD explicitly requires security/DevSecOps. | `experience_swisscom.md` SW-5, `achievement_reframing_guide.md`, `skills_taxonomy.md` (3 rows) |
+5 -2
View File
@@ -10,7 +10,7 @@
- **Degree suffix:** M.Eng. - **Degree suffix:** M.Eng.
- **Email:** dennis@thiessen.io - **Email:** dennis@thiessen.io
- **Phone:** +41 795 955 585 - **Phone:** +41 795 955 585
- **Location:** Bern, Switzerland - **Location (contact line):** **Bern, Switzerland** by default. Use **Thun, Switzerland / Thun, Schweiz** for roles in **Thun or its immediate surroundings** - the user lives in Thun, and local residency at the employer's own location is a real screening signal for traditional Swiss employers (user-decided 2026-08-27). This applies to the **contact line only**; a position's own location stays factual, e.g. the Swisscom entry keeps Bern.
- **LinkedIn:** linkedin.com/in/dennis-thiessen - **LinkedIn:** linkedin.com/in/dennis-thiessen
- **Google Scholar:** [leave blank — not applicable] - **Google Scholar:** [leave blank — not applicable]
- **ORCID:** [leave blank — not applicable] - **ORCID:** [leave blank — not applicable]
@@ -52,6 +52,7 @@ Verified errors to never re-introduce. Add entries as you catch mistakes.
| Correction | Details | | Correction | Details |
|-----------|---------| |-----------|---------|
| Capgemini omitted from all documents | **Standing user preference.** Capgemini Deutschland GmbH (Nov. 2014 - Mai 2015) must **never** appear on a resume, CV or cover letter - only six months, and the user does not want the short-stay impression. The visible chronology starts at **Generali, Mai 2015**. **The resulting Nov. 2014 - Mai 2015 gap is intentional and must never be "fixed" or explained away.** Any tenure claim in a summary line ("over ten years") is measured against the visible record from Mai 2015. Regressed once into the RUAG C5I draft on 2026-08-27 because this rule lived only in memory. |
| Degree name | B.Eng. official name: "Information and Telecommunication Technologies". M.Eng. official name: "Computer Aided Engineering" with focus in Software Design and Software Engineering. Use "Software Design & Engineering" as the focus description on resumes — more recognizable than the official programme name. | | Degree name | B.Eng. official name: "Information and Telecommunication Technologies". M.Eng. official name: "Computer Aided Engineering" with focus in Software Design and Software Engineering. Use "Software Design & Engineering" as the focus description on resumes — more recognizable than the official programme name. |
| Education dates | B.Eng. **Oct 2009 Oct 2012** (start 10/2009, finished 01.10.2012). M.Eng. **Apr 2012 Oct 2013** (01.04.2012 01.10.2013). Programmes overlap by design — do NOT "fix" the overlap. Both at Universität der Bundeswehr München. | | Education dates | B.Eng. **Oct 2009 Oct 2012** (start 10/2009, finished 01.10.2012). M.Eng. **Apr 2012 Oct 2013** (01.04.2012 01.10.2013). Programmes overlap by design — do NOT "fix" the overlap. Both at Universität der Bundeswehr München. |
| Swisscom title | Senior: Oct 2023 Apr 2025. Staff (Engineer IV): Apr 2025 Present. Use "Staff Data, Analytics & AI Engineer" for current role; note promotion if space allows. | | Swisscom title | Senior: Oct 2023 Apr 2025. Staff (Engineer IV): Apr 2025 Present. Use "Staff Data, Analytics & AI Engineer" for current role; note promotion if space allows. |
@@ -114,4 +115,6 @@ These are copied verbatim from your template every time.
- **Local alternative:** 2-page Swiss/DACH profile - **Local alternative:** 2-page Swiss/DACH profile
- **Cover letter:** Generate only when required or when it adds information not visible in the resume - **Cover letter:** Generate only when required or when it adds information not visible in the resume
- **Academic CV:** Not a default target. Generate only for an explicitly academic/research application - **Academic CV:** Not a default target. Generate only for an explicitly academic/research application
- **Output .tex files ONLY** — user compiles locally - **The `.tex` is the deliverable and the source of truth** - never hand-edit a PDF, and always regenerate from the source
- **Compile the PDF into the application's own `output/` folder** so the user can review and approve it. A `.tex` alone is not reviewable for him. Never leave the only PDF in a temp directory, and never leave a stale pre-edit PDF next to the deliverable (user-reported 2026-08-27).
- **If a submission-named copy exists** (e.g. `Dennis_Thiessen_Lebenslauf.pdf`), **refresh it on every recompile.** It is a copy, not a build target, so it silently goes stale under exactly the filename that gets attached to an application.
+22 -2
View File
@@ -289,8 +289,28 @@ COMPANIES = [
# Telenor Norge (Teamtailor) — Nordic telco; Swisscom is the direct domain analogue # Telenor Norge (Teamtailor) — Nordic telco; Swisscom is the direct domain analogue
# and Dennis worked in Norway before (Vizrt, Bergen). NOTE: the old Workday tenant # and Dennis worked in Norway before (Vizrt, Bergen). NOTE: the old Workday tenant
# telenorgroup.wd3.myworkdayjobs.com is dead (HTTP 422 on /wday/cxs, 2026-07-29) — # telenorgroup.wd3.myworkdayjobs.com is dead (HTTP 422 on /wday/cxs, 2026-07-29) —
# Telenor migrated to Teamtailor. Slug telenorgroup is a near-empty group-HQ board; # Telenor migrated to Teamtailor. telenornorway is the real Norway board (redirects
# telenornorway is the real Norway board (redirects to careers.telenor.no). # to careers.telenor.no).
# TRAP — slug telenorgroup is NOT a "near-empty group-HQ board" as this comment used
# to claim (corrected 2026-08-27): it is a claimed board titled "Sandbox: Telenor
# Shared Services" serving 18 phantom listings whose newest is 2024-11-11, including
# plausible-looking "Lead Software Engineer" / "Frontend Developer - Oslo" roles. None
# of its titles hit the DEMO_TITLES fingerprint in fetch_teamtailor(), so that guard
# would NOT catch it — do not widen DEMO_TITLES to cover this. That guard is for
# *unclaimed* slugs served Teamtailor's demo seed set; this is a claimed board serving
# years-stale data, a different failure mode (a newest-item age threshold is the fix,
# if one is ever wanted). Never point this entry at telenorgroup.
# Sibling Telenor boards probed 2026-08-27, all rejected, do not re-probe:
# telenorcyberdefence (3 roles, newest 2025-10-06 — dormant), telenordenmark (4 roles:
# retail sales, praktikant, legal student — zero engineering, and it would run under
# the default CH/DK policy rather than norway_only, so it is pure noise),
# telenoramp / telenormaritime / telenorsatellite / telenorsverige / telenorkystradio /
# telenorbusiness (all HTTP 404 — no such board).
# THROUGHPUT (measured 2026-08-27): the live board carries 4-5 roles at a time and is
# mostly Norwegian-language ops/security. Exactly one relevant role has surfaced —
# Platform Engineer, Core Automation (job 7829423, posted 2026-06-01, score 5), first
# reported 2026-08-18 and HTTP 410 Gone by 2026-08-27. The feed did NOT silently drop
# it; it genuinely closed. Expect roughly one tailorable role per quarter here.
# CAVEAT: most Telenor Norge postings require Norwegian ("norsk og engelsk") and are # CAVEAT: most Telenor Norge postings require Norwegian ("norsk og engelsk") and are
# Oslo/Trondheim onsite-hybrid — verify both per role before tailoring. # Oslo/Trondheim onsite-hybrid — verify both per role before tailoring.
# Norwegian-language titles/descriptions score ~0 under the English eng keyword # Norwegian-language titles/descriptions score ~0 under the English eng keyword
+23 -2
View File
@@ -31,8 +31,9 @@
"evidence_fit": 79.0, "evidence_fit": 79.0,
"hard_gate": "pass", "hard_gate": "pass",
"channel": "weak", "channel": "weak",
"outcome": "applied", "outcome": "rejected_no_interview",
"submitted": "2026-07-29" "submitted": "2026-07-29",
"rejection_date": "2026-08-27"
}, },
{ {
"company": "SBB", "company": "SBB",
@@ -56,6 +57,26 @@
"hard_gate": "pass", "hard_gate": "pass",
"channel": "weak", "channel": "weak",
"outcome": "applied" "outcome": "applied"
},
{
"company": "Schweizer Armee - Kommando Cyber",
"role": "DevOps Engineer III (Data Platform)",
"application_date": "2026-08-27",
"fit_class": "core",
"evidence_fit": 79.0,
"hard_gate": "pass",
"channel": "weak",
"outcome": "applied"
},
{
"company": "RUAG MRO Holding AG (Business Area C5I)",
"role": "AI Engineer C5I (w/m/d), Thun",
"application_date": "2026-08-27",
"fit_class": "stretch",
"evidence_fit": 74.0,
"hard_gate": "fail",
"channel": "weak",
"outcome": "applied"
} }
] ]
} }
+40 -5
View File
@@ -1701,11 +1701,11 @@
"date": "2026-07-28" "date": "2026-07-28"
}, },
"https://www.finn.no/job/fulltime/ad.html?finnkode=469067315": { "https://www.finn.no/job/fulltime/ad.html?finnkode=469067315": {
"company": "", "company": "Aker BP ASA",
"title": "", "title": "Data Product Architect, AI-ready Data Products",
"decision": "applied", "decision": "rejected",
"note": "Aker BP ASA - Data Product Architect, AI-ready Data Products (FINN 469067315). SUBMITTED 2026-07-30, ahead of 2026-08-02 deadline. Evidence Fit 79/100, Document Quality 93/100, hard gate PASS, channel weak. Stavanger/Oslo/Trondheim, English working language.", "note": "Aker BP ASA - Data Product Architect, AI-ready Data Products (FINN 469067315). SUBMITTED 2026-07-30, ahead of 2026-08-02 deadline. Evidence Fit 79/100, Document Quality 93/100, hard gate PASS, channel weak. Stavanger/Oslo/Trondheim, English working language. REJECTED 2026-08-27, no interview - ~28 days to disposition (records differ on the submission date: session file and cohort say 2026-07-29, this note and CLAUDE.md say 2026-07-30). Cold channel; the optional follow-up email to Per Olav Marthinsen stayed an open action with no record of it being sent. Cohort evidence-first-2026-01 slot stays consumed (adjacent 1 of 2); the rejection does not free it. Norway remains an active, selective lane - NATO JWC Stavanger is still open, and the user has said Equinor and other strong Norwegian employers stay in scope.",
"date": "2026-07-31" "date": "2026-08-27"
}, },
"https://www.google.com/about/careers/applications/jobs/results/93922217108087494-software-engineer-iii-business-home?location=Switzerland": { "https://www.google.com/about/careers/applications/jobs/results/93922217108087494-software-engineer-iii-business-home?location=Switzerland": {
"company": "Google", "company": "Google",
@@ -1809,5 +1809,40 @@
"decision": "applied", "decision": "applied",
"note": "Submitted 2026-08-26. Adjacent, Evidence Fit 71, Document Quality ~91 est (critique scored 86 pre-Tier-1). 2pp resume + 1pp CL, both validator PASS. IMPORTANT FINDING: the application form's preferred-work-location dropdown offered NO Zurich option, despite the JD body saying 'Miami, Zurich or New York' and the site's own Zurich filter returning this req. Careers site is operated by Citadel Enterprise Americas LLC. Treat the Zurich seat as unconfirmed for any future Citadel application - check the form before investing. Working-model question (5-day onsite?) never resolved and may now be moot. Channel cold; user applied with low expectation.", "note": "Submitted 2026-08-26. Adjacent, Evidence Fit 71, Document Quality ~91 est (critique scored 86 pre-Tier-1). 2pp resume + 1pp CL, both validator PASS. IMPORTANT FINDING: the application form's preferred-work-location dropdown offered NO Zurich option, despite the JD body saying 'Miami, Zurich or New York' and the site's own Zurich filter returning this req. Careers site is operated by Citadel Enterprise Americas LLC. Treat the Zurich seat as unconfirmed for any future Citadel application - check the form before investing. Working-model question (5-day onsite?) never resolved and may now be moot. Channel cold; user applied with low expectation.",
"date": "2026-08-26" "date": "2026-08-26"
},
"https://careers.axpo.com/jobs/8263436-staff-plattform-engineer-w-m-d": {
"company": "",
"title": "",
"decision": "skip",
"note": "User decision 2026-08-27: not of interest. Baden is a 90min commute from Thun and Axpo is unlikely to pay materially above his current ~140k. RULE: for a commute that long the package must be much better - BIS-style tax-free or FAANG-like comp. Azure + Terraform are also named requirements with 0 canonical evidence, but that was NOT the deciding factor.",
"date": "2026-08-27"
},
"https://jobs.ruag.ch/offene-stellen/ai-engineer-c5i/4afaa9aa-74c1-4b4d-9232-cf65651ce8ec": {
"company": "RUAG C5I",
"title": "AI Engineer C5I (Thun)",
"decision": "applied",
"note": "SUBMITTED 2026-08-27 via jobs.ruag.ch (portal only; email and post are refused). Application ID 18027. Cohort evidence-first-2026-01 now 6/10 and the sole Stretch slot is CONSUMED (stretch 1/1). Evidence Fit 74/100, strategic Stretch, strict title-capability hard gate FAIL - all knowingly accepted under the user's explicit Phase 0 override; R1 (build/operate an internal AI-/LLM platform incl. compute cluster) and R2 (in-house LLM solutions, connectors, retrieval/document solutions) are Adjacent, not Direct. Document Quality 93/100 after a full critique-and-fix round (85 pre-edit), truth and provenance 24/25, zero Tier 1 findings at Round 2. Submitted package: German Swiss/DACH resume, 2 pages, 13 bullets, plus a German motivation letter, 1 page, 295 words. Both validators PASS with 0 warnings, 0 boxes, clean two-pass compiles, text-order checks and visual QA of every page. Positioning: Staff Data, Analytics & AI Engineer (his canonical title) with production ML-inference integration, Kubernetes/Linux/Ansible automation, current LLM application configuration and the canonical BW-1 officer career. PP-3 (private self-hosted Debian server, hardening) carries the current Linux/ops evidence since BS-6 ended Dec 2022. The letter names the AI-platform gap in one sentence and pivots to the operations/platform side, and connects SW-5 (Security Champion 2025/2026) to C5I's stated DevSecOps model. No RAG, retrieval, compute-cluster, GPU, model-training or LLM-platform ownership claim anywhere. Channel WEAK - cold portal submit; Marco Heinzen's published direct line (+41 79 568 14 96) was never used. STILL UNRESOLVED and now live screening topics: compensation (no band published; external samples suggest downside risk against the 180k bar), PSP/project eligibility for a German citizen with a Swiss B permit, and whether the role is lateral or a down-level move against current Staff + Component Owner scope.",
"date": "2026-08-27"
},
"https://nvidia.wd5.myworkdayjobs.com/job/Switzerland-Zurich/Senior-Site-Reliability-Engineer--DGX-Cloud_JR2021427-1": {
"company": "",
"title": "",
"decision": "shortlist",
"note": "User flagged interesting 2026-08-27. NVIDIA JR2021427, posted 2026-08-20. KEY: Workday additionalLocations lists 'Switzerland, Remote' alongside Zurich - the commute constraint that killed Axpo does not apply, which re-ranks this level with RUAG on practical grounds. Comp is the FAANG-like shape he named as worth a trip anyway. Fit: K8s at scale, Python, observability (Prometheus/Grafana/ELK) Direct; GPU cluster ops across AWS/GCP/Azure/OCI. GAPS, both named requirements with 0 canonical evidence: (a) infrastructure automation - Terraform/Ansible/Chef/Puppet, Terraform is a recorded hard gap and the Kraken SRE rejection was exactly this shape; (b) SRE practice as a discipline - SLO/SLI/error budgets, on-call rotation, incident command, no SRE title. Also '10+ years operating production services'. NOTE: the scout's constructed URL 404s - the real apply link needs the NVIDIAExternalCareerSite segment: https://nvidia.wd5.myworkdayjobs.com/NVIDIAExternalCareerSite/job/Switzerland-Zurich/Senior-Site-Reliability-Engineer--DGX-Cloud_JR2021427-1",
"date": "2026-08-27"
},
"https://www.bis.org/careers/vacancies/jr100420.htm": {
"company": "",
"title": "",
"decision": "maybe",
"note": "User flagged interesting 2026-08-27; NOT recorded as shortlist because the JD read is worse than the title suggested. BIS Basel, Platforms team in ITS, 3-year fixed term, deadline 17 Sept 2026, hires all nationalities with relocation support, English corporate language - all fine and consistent with jr100429. PROBLEM: the title-defining capability is DBA, not platform data engineering. Purpose line is enterprise database platforms - Microsoft SQL Server, PostgreSQL, Oracle - with 'deep domain expertise in database technologies', DB administration/availability/lifecycle, and DB certifications as an advantage. That is a Gap, not a stretch. Same shape as the AWS Senior FDE NO-GO on 2026-08-18: minimum quals largely pass (K8s, IaC, CI/CD, observability, cloud all Direct) but the capability the title is built on is unsupported. Secondary issue: jr100429 has been open at BIS since 2026-07-10, so this would stack a second application at one org - the Snowflake precedent. Deadline is 3 weeks out, no urgency pressure.",
"date": "2026-08-27"
},
"https://jobs.admin.ch/offene-stellen/devops-engineer-iii-data-platform/752ded37-1753-4ac8-946a-b0c958d4424a": {
"company": "Schweizer Armee - Kommando Cyber",
"title": "DevOps Engineer III (Data Platform)",
"decision": "applied",
"note": "Submitted 2026-08-27. Ref JRQ$540-19848, Zimmerwald. Core, Evidence Fit 79, Document Quality 92, hard gate PASS, channel weak. German 2-page CV plus 1-page motivation letter; the six-year Bundeswehr officer career is included as military-context and motivation evidence. User explicitly accepted the critique's remaining BS-1 wording issue ('ohne manuellen Eingriff') as good enough and submitted without the proposed correction. Honest gaps at submission: physical datacenter work, Pull-GitOps as a named practice, GPGPU, ClickHouse and second Swiss official language. Lohnklasse and Engineer-III level were not recorded as clarified.",
"date": "2026-08-27"
} }
} }
@@ -1,7 +1,7 @@
# Dennis Thiessen — Certifications Extraction # Dennis Thiessen — Certifications Extraction
> One file for all cert PDFs. Added as each cert is processed. > One file for all cert PDFs. Added as each cert is processed.
> Last updated: 2026-03-28 > Last updated: 2026-08-27
--- ---
@@ -16,6 +16,7 @@
| 5 | Projektleiter Baustein A/IT — Das IT-Projektmanagement (seminar) | Integrata AG | 15 Sep 2014 | N/A | Seminar-Nr. 2113 | 5-day attendance (Teilnahmebestätigung). NOT a cert — do not list on resume/CV. Topics: IT project planning, control, risk analysis. Context: during Bundeswehr period. | | 5 | Projektleiter Baustein A/IT — Das IT-Projektmanagement (seminar) | Integrata AG | 15 Sep 2014 | N/A | Seminar-Nr. 2113 | 5-day attendance (Teilnahmebestätigung). NOT a cert — do not list on resume/CV. Topics: IT project planning, control, risk analysis. Context: during Bundeswehr period. |
| 6 | AI for Trading Nanodegree | Udacity (co-created with WorldQuant) | 13 May 2021 | N/A | confirm.udacity.com/DJ9QTAH9 | Quantitative finance + ML for trading; completed during Bosch period. Relevant for quant/fintech roles; niche signal for blockchain/crypto interest. | | 6 | AI for Trading Nanodegree | Udacity (co-created with WorldQuant) | 13 May 2021 | N/A | confirm.udacity.com/DJ9QTAH9 | Quantitative finance + ML for trading; completed during Bosch period. Relevant for quant/fintech roles; niche signal for blockchain/crypto interest. |
| 7 | AWS Certified Solutions Architect Associate | Amazon Web Services (via Alpine Testing / CertMetrics) | 26 Sep 2024 | 26 Sep 2027 (active) | cp.certmetrics.com/amazon — verified 2026-03-27 | ACTIVE. High-value cert for Data Platform / Infra and Staff Data Engineer roles. Pairs well with Udacity DataEng AWS nanodegree. | | 7 | AWS Certified Solutions Architect Associate | Amazon Web Services (via Alpine Testing / CertMetrics) | 26 Sep 2024 | 26 Sep 2027 (active) | cp.certmetrics.com/amazon — verified 2026-03-27 | ACTIVE. High-value cert for Data Platform / Infra and Staff Data Engineer roles. Pairs well with Udacity DataEng AWS nanodegree. |
| 8 | IBM AI Engineering (Professional Certificate, 6 courses) | IBM via Coursera | 4 Jun 2020 | N/A (no expiry) | coursera.org/verify/professional-cert/3ZBZFVAL6A34 | Name: "Dennis Thießen" (ß variant). **Verified against the certificate PDF 2026-08-27** (`C:\myCloud\Bewerbungsunterlagen\Zeugnisse\Zertifikate\cert_IBM_AI_Engineering.pdf`). Courses: Machine Learning with Python; Scalable ML on Big Data with Apache Spark; Intro to Deep Learning & Neural Networks with Keras; Deep Neural Networks with **PyTorch**; Building Deep Learning Models with **TensorFlow**; AI Capstone Project with Deep Learning. This is the source of the `TensorFlow/Keras` **and** `PyTorch` entries in `claims.json` — both stay `certification-context-only`. Explicitly non-credit: the certificate states it confers no grade, course credit or degree, so never present it as an academic qualification. |
--- ---
@@ -152,6 +152,6 @@ All hooks verified against first-party or canonical sources. **No unverified cla
- Critique: **CURRENT** — Evidence Fit 79/100 Adjacent, Document Quality 93/100, hard gate PASS, Channel Weak. 3 Tier 1 findings applied (architecture vocabulary, Languages line, catalogue/adoption terms). See `critique_akerbp_data_product_architect.md`. - Critique: **CURRENT** — Evidence Fit 79/100 Adjacent, Document Quality 93/100, hard gate PASS, Channel Weak. 3 Tier 1 findings applied (architecture vocabulary, Languages line, catalogue/adoption terms). See `critique_akerbp_data_product_architect.md`.
- Finalized: **YES 2026-07-29**`Dennis_Thiessen_Resume.pdf`, `Dennis_Thiessen_Cover_Letter.pdf`; cohort entry added (evidence-first-2026-01, adjacent 1/2) - Finalized: **YES 2026-07-29**`Dennis_Thiessen_Resume.pdf`, `Dennis_Thiessen_Cover_Letter.pdf`; cohort entry added (evidence-first-2026-01, adjacent 1/2)
- Pre-submission actions outstanding: **attach diploma/grade transcript** (required by posting); optional cold email to Per Olav Marthinsen - Pre-submission actions outstanding: **attach diploma/grade transcript** (required by posting); optional cold email to Per Olav Marthinsen
- Application/outcome: **SUBMITTED 2026-07-29** (4 days before the 2026-08-02 deadline). Cohort outcome set to `applied`. Awaiting response. - Application/outcome: **SUBMITTED 2026-07-29** (4 days before the 2026-08-02 deadline). **CLOSED — REJECTED 2026-08-27, no interview, ~28 days to disposition.** Cohort outcome set to `rejected_no_interview` (evidence-first-2026-01, Adjacent slot stays consumed — a rejection does not free it); decision log updated. Cold channel: the optional follow-up email to Per Olav Marthinsen was never actioned, so this went in as a pure cold submit. Package was validator PASS with no Tier 1 truth findings — **this outcome does not implicate document quality on its own**, and per `application_strategy.md` §38/§74 no positioning change follows from a single rejection. Note: `CLAUDE.md` and the decision log record the submission as 2026-07-30 — a one-day inconsistency with this file, left unreconciled.
- Next: `/make-cl output/AkerBP_Data_Product_Architect/session_akerbp_data_product_architect.md` - Next: `/make-cl output/AkerBP_Data_Product_Architect/session_akerbp_data_product_architect.md`
- Then: `/critique output/AkerBP_Data_Product_Architect/session_akerbp_data_product_architect.md` - Then: `/critique output/AkerBP_Data_Product_Architect/session_akerbp_data_product_architect.md`
@@ -0,0 +1,130 @@
https://jobs.admin.ch/offene-stellen/devops-engineer-iii-data-platform/752ded37-1753-4ac8-946a-b0c958d4424a
DevOps Engineer III (Data Platform) - Schweizer Armee - Kommando Cyber Kdo Cy
-->
Übersicht
Kontakt
Über uns
Benefits
Ähnliche Stellen
Stellen teilen
Drucken
Job-Abo einrichten
Später bewerben
Interessiert?
Möchten Sie sich bewerben? Dann senden Sie sich die Stelle per E-Mail zu und bewerben Sie sich bequem von zu Hause aus.
E-Mail
Link senden
Der Link zu dieser Stelle wurde an die eingegebene E-Mail-Adresse verschickt.
DevOps Engineer III (Data Platform)
Die Schweiz mitgestalten
DevOps Engineer III (Data Platform)
Schweizer Armee - Kommando Cyber Kdo Cy
Zimmerwald | 80-100% (Jobsharing möglich)
Eintrittsdatum:
nach Vereinbarung
Anstellungsart:
unbefristet
Referenz-Nr.:
JRQ$540-19848
Arbeitsort:
Eichacher, 3086 Wald
Diesen Beitrag kannst du leisten
Moderne IaC- und GitOps-Lösungen planen, implementieren und betreiben sowie den gesamten Deployment-Zyklus verantworten
MLOps-Umgebungen für das Deployment, Monitoring und den zuverlässigen Betrieb von KI- und Machine-Learning-Modellen entlang ihres gesamten Lebenszyklus bis hin zur GPGPU-Hardware entwerfen, betreiben, automatisieren und weiterentwickeln
Komplexe Linux-Systemlandschaften für den Ende-zu-Ende-Betrieb einer IKT-Schicht für eine Datenplattform administrieren, warten und kontinuierlich optimieren, um einen stabilen und performanten Betrieb sicherzustellen
Linux-Systeme ganzheitlich administrieren, Performance optimieren sowie System-Hardening und Security-Konfigurationen umsetzen
Monitoring-, Logging- und Observability-Lösungen betreiben, weiterentwickeln und optimieren, um einen zuverlässigen Systembetrieb sicherzustellen
Die physische Infrastruktur im Rechenzentrum mit Server-, Netzwerk- und Datacenter-Komponenten betreuen sowie Installationen und Wartungsarbeiten unterstützen
Das macht dich einzigartig
Abgeschlossene Ausbildung im IT-Bereich HF/FH sowie mehrere Jahre Praxis im Engineering und im Betrieb von komplexen IT Systemen
Fundierte DevOps-Kompetenz durch mehrjährige Erfahrung im Aufbau, Betrieb und in der Automatisierung moderner Linux-Infrastrukturen sowie umfassende Kenntnisse in Infrastructure-as-Code, GitOps und zugehörigen Prozessen
Streben nach Exzellenz mit hoher Lernbereitschaft und Offenheit für ganzheitliche, elegante IKT-Lösungen sowie innovative Ansätze abseits des Mainstreams wie Dhall, Pull-GitOps und «Dew-» sowie «Fog-Computing»-Paradigmen
Hands-on-Mentalität sowie eine selbstständige und teamorientierte Persönlichkeit mit Freude an der Arbeit über den gesamten Technologie-Stack hinweg von der physischen Infrastruktur im Rechenzentrum bis hin zu automatisierten Plattform- und Big-Data-Umgebungen wie ClickHouse und Kafka
Ein tadelloser Leumund sowie die Fähigkeit, sich in ein nachrichtendienstliches Umfeld zu integrieren und dabei jederzeit diskret zu handeln, werden vorausgesetzt
Aktive Kenntnisse einer zweiten Amtssprache sowie gute Englischkenntnisse
Auf den Punkt gebracht
Du bist Teil eines Data-Science-Teams im Bereich der Verarbeitung von erfassten zivilen und militärischen Kommunikationsdaten. Die daraus gewonnenen nachrichtendienstlichen Erkenntnisse unterstützen den NDB und den MND und leisten damit einen wichtigen Beitrag zur Sicherheitspolitik der Schweiz. Als DevOps Engineer III bist du fachlich mitverantwortlich für den Entwurf, die Umsetzung und den Betrieb einer grossen, verteilten Dateninfrastruktur.
Eintrittsdatum:
nach Vereinbarung
Anstellungsart:
unbefristet
Referenz-Nr.:
JRQ$540-19848
Arbeitsort:
Eichacher, 3086 Wald
Fragen zur Stelle
Marcel Matthey-Doret
Chef Centers of Excellence CEA
+41 58 46 78409
Jetzt bewerben
Sind Sie aktuell beim Bund angestellt?
Ja
Nein
Fragen zur Stelle
Marcel Matthey-Doret
Chef Centers of Excellence CEA
+41 58 46 78409
Auf den Punkt gebracht
Du bist Teil eines Data-Science-Teams im Bereich der Verarbeitung von erfassten zivilen und militärischen Kommunikationsdaten. Die daraus gewonnenen nachrichtendienstlichen Erkenntnisse unterstützen den NDB und den MND und leisten damit einen wichtigen Beitrag zur Sicherheitspolitik der Schweiz. Als DevOps Engineer III bist du fachlich mitverantwortlich für den Entwurf, die Umsetzung und den Betrieb einer grossen, verteilten Dateninfrastruktur.
Dein Einsatz für Sicherheit und Freiheit
Das Kommando Cyber (Kdo Cy) steht für Kompetenz in den Bereichen Cyber und Digitalisierung. Wir vereinen die Begeisterung für unsere Aufgabe mit Know-how, Innovation, modernsten Technologien und agilen Arbeitsweisen. Wir erbringen sichere, robuste und resiliente Informatikleistungen für die Schweizer Armee und unsere Partner im Sicherheitsverbund Schweiz. Damit ermöglicht das Kdo Cy der Schweizer Armee den notwendigen Wissens- und Entscheidvorsprung für eine sichere Schweiz.
Die Schweizer Armee beschäftigt über 9'000 Mitarbeitende in vier militärischen und rund 200 zivilen Berufen und dies an 110 Standorten schweizweit. Auch für den Nachwuchs ist gesorgt: Die Schweizer Armee bildet in über 30 Berufen Lernende aus.
Weiter
Zurück
Link zu mehr Informationen
Das bieten wir
#F7B4B8
Arbeiten für die Schweiz
Wir setzen uns für das Erfolgsmodell Schweiz ein und arbeiten zum Wohl der Bevölkerung.
#F7B4B8
Arbeiten für die Schweiz
Wir setzen uns für das Erfolgsmodell Schweiz ein und arbeiten zum Wohl der Bevölkerung.
#B8E1D8
Gelebte Vielfalt
Dank Chancengleichheit entfalten wir unsere Kompetenzen und bringen unterschiedliche Perspektiven ein.
#B8E1D8
Gelebte Vielfalt
Dank Chancengleichheit entfalten wir unsere Kompetenzen und bringen unterschiedliche Perspektiven ein.
#FFF0BB
Gesund am Arbeitsplatz
Wir unterstützen und beraten unsere Mitarbeitenden im Bereich der physischen und psychischen Gesundheit.
#FFF0BB
Gesund am Arbeitsplatz
Wir unterstützen und beraten unsere Mitarbeitenden im Bereich der physischen und psychischen Gesundheit.
Alle Benefits
Fragen zur Stelle
Marcel Matthey-Doret
Chef Centers of Excellence CEA
+41 58 46 78409
Jetzt bewerben
Jetzt bewerben
Sind Sie aktuell beim Bund angestellt?
Ja
Nein
-->
Zusätzliche Informationen
Eine Anstellung bei der Schweizer Armee macht Sinn und bringt viele Vorteile mit sich. Überzeuge dich auf 
armee.ch/vorteile
.
Interessiert an Jobsharing? Du kannst dich einzeln oder mit Partner/-in bewerben. Auch wenn ihr euch im Duo bewerbt: Reicht eure Bewerbungen einzeln ein und gebt den Namen der Partnerin/des Partners im Bewerbungskonto an.
Angebote von Personalvermittlern werden nicht berücksichtigt.
Die nächsten Schritte
Frauen sind in unserer Verwaltungseinheit noch untervertreten. Ihre Bewerbungen sind daher besonders willkommen.
Ähnliche Stellen
Staatssekretariat für Wirtschaft SECO
ICT DevOps Engineer Data & Analytics Senior
Bern, Schweiz | 100-100% (Jobsharing möglich)
Bundesamt für Informatik und Telekommunikation BIT
ICT-System-Ingenieur/-in Senior Container Plattform
Zollikofen, Schweiz (und Homeoffice) | 80-100%
Bundesamt für Informatik und Telekommunikation BIT
Datenbank-Administrator/-in Senior (1025)
Zollikofen, Schweiz (und Homeoffice) | 80-100%
Rechtliche Grundlagen
Job-Abo einrichten
Rechtliche Grundlagen
Jetzt bewerben
Sind Sie aktuell beim Bund angestellt?
Ja
Nein
@@ -0,0 +1,156 @@
# Critique v3: Kdo Cy, DevOps Engineer III (Data Platform)
**Stand:** 27. August 2026, nach Edit 2 mit Bundeswehr-Offizierslaufbahn und vollständigem Sprachpass.
> **Submission note, 27. August 2026:** Der Nutzer hat die Bewerbung nach Prüfung dieser Critique als gut genug bewertet und unverändert eingereicht. Der Tier-1-Fund zu *„ohne manuellen Eingriff“* bleibt als bekannte, bewusst akzeptierte Abweichung dokumentiert; er wurde nicht nachträglich aus den eingereichten Dokumenten entfernt.
| Achse | Aktuelles Ergebnis |
|---|---|
| Evidence Fit | **79/100, Core (unterer Bereich)** |
| Hard Gate | **PASS** |
| Document Quality | **92/100** |
| Channel Strength | **Weak** |
| Einreichungsstatus | **Noch nicht freigeben: ein Tier-1-Claim muss korrigiert werden** |
Die Offizierslaufbahn ist ein echter Differenzierungsfaktor für diesen Arbeitgeber. Sie verbessert die Glaubwürdigkeit der Motivation und die militärische Anschlussfähigkeit, ersetzt aber keine technische Militär-, Nachrichtendienst- oder Clearance-Evidenz. Deshalb bleibt der Evidence-Fit-Score nach unabhängiger Neubewertung bei 79.
## 1. Fit Verdict und Hard-Gate-Audit
**Verdict: Core, Hard Gate PASS.** Dennis deckt den Titelkern inzwischen ausreichend ab: professionelle Linux-Administration und Ansible-Automatisierung bei Bosch, aktueller Datenplattformbetrieb bei Swisscom, Kubernetes/CI/CD, Kafka, Observability und containerisiertes ML-Deployment. Die einzelnen Belege liegen nicht alle in derselben aktuellen Rolle, ergeben zusammen aber ein belastbares DevOps-/Data-Platform-Profil.
| Bereich | Einstufung | Begründung |
|---|---|---|
| IT-Abschluss und Betrieb komplexer Systeme | Direct | M.Eng.; langjährige Engineering- und Betriebspraxis |
| Linux-Infrastruktur und IaC | Direct-to-Adjacent | Bosch Linux/Ansible sowie CloudFormation sind Direct; das vom JD genannte Pull-GitOps bleibt Gap |
| MLOps und GPGPU | Adjacent | Produktive ML-Inferenzintegration ist stark; GPGPU und vollständiger ML-Lebenszyklus sind nicht belegt |
| Data Platform und Big Data | Direct-to-Adjacent | Kafka, Datenstrecken, AWS, Hadoop/Impala und Data Products sind Direct; ClickHouse fehlt |
| Physische Rechenzentrumsarbeit | Gap | Kein belegter Umgang mit Server-, Netzwerk- oder Datacenter-Hardware |
| Nachrichtendienstliches Umfeld / PSP | Constraint, geklärt | Deutsche Staatsangehörigkeit und B-Bewilligung sind laut Nutzerangabe zulässig; eine PSP wird nicht behauptet |
| Zweite Amtssprache | Soft Gap | Vom Nutzer als Wunschkriterium geklärt; bleibt ein Wettbewerbsvorteil anderer Kandidaten |
| Militärischer Kontext | Adjacent | Sechsjährige Offizierslaufbahn ist Direct als Organisationskontext, aber kein Nachweis für Nachrichtendienst, Cyber, Einsatz oder Clearance |
Der weiterhin offene physische Datacenter-Anteil ist ernst, aber nicht allein titeldefinierend. Die Dokumente behandeln ihn korrekt als Motivation und nicht als vorhandene Berufserfahrung.
## 2. Evidence Fit
| Dimension | Gewicht | Score | Begründung |
|---|---:|---:|---|
| Required qualifications | 35 | **30** | Abschluss, Engineering, Linux/IaC und Englisch sind stark; Pull-GitOps, physische Infrastruktur und zweite Amtssprache bleiben schwächer |
| Core responsibilities | 25 | **19** | Betrieb, Automatisierung, MLOps, Datenplattform und Observability sind belegt; RZ-Hardware, GPGPU und vollständiges GitOps fehlen |
| Level and ownership | 15 | **10** | Component Owner und Application Owner passen; Engineer III wirkt gegenüber aktuellem Staff-Scope lateral bis leicht darunter |
| Recency and depth | 10 | **9** | Kubernetes, Kafka, Python, AWS und CI/CD sind aktuell; die tiefste Linux-/Ansible-Evidenz endet 2022 |
| Domain/tool transfer | 10 | **7** | Impala/Oracle übertragen sich auf ClickHouse-Grundmuster; CI/CD ist kein Pull-GitOps. Die Offizierslaufbahn stärkt den Kontext, nicht die technische Funktionsdeckung |
| Practical constraints | 5 | **4** | Kurzer Arbeitsweg, Arbeitserlaubnis und unbefristete Stelle passen; Lohnklasse und Level bleiben offen |
| **Total** | **100** | **79** | **Core, unterer Bereich; Hard Gate PASS** |
## 3. Document Quality
| Dimension | Gewicht | Score | Begründung |
|---|---:|---:|---|
| Truth and provenance | 25 | **23** | Fast alle Claims sind sauber scoped. Ein absoluter Ergebnisclaim bei Bosch überschreitet die kanonische Evidenz und ist Tier 1 |
| Information hierarchy | 20 | **19** | Zielprofil, Swisscom, Linux/Ansible und Bundeswehr-USP sind sofort sichtbar. Das Kurzprofil belegt allerdings fünf gerenderte Zeilen statt der vorgesehenen zwei bis drei |
| Bullet evidence and impact | 20 | **17** | Technisch konkret und ownership-sicher; kaum verifizierte Kennzahlen. Einige Bullets sind listenlastig, der Bosch-Resultatclaim ist zu absolut |
| Relevance and terminology | 15 | **14.5** | Sehr gute Deckung von Linux, IaC, MLOps, Deployment, Kafka, Observability und Betrieb; echte Gaps werden nicht mit Keywords kaschiert |
| Skills evidence | 10 | **9.5** | Alle sichtbaren Skills sind belegbar und nach Quelle kontextualisiert; C++ und JavaScript wurden sinnvoll aus dem Skills-Block entfernt |
| Mechanics and readability | 10 | **9** | Saubere PDFs, gute Extraktion, keine Box- oder Layoutfehler. Kleine Abzüge für eine unnatürliche IaC-Klammerung, listenreiche Kadenz und zwei aufeinanderfolgende `Entwickelte`-Einstiege |
| **Total** | **100** | **92** | **Hohe Dokumentqualität, aber noch nicht freigabefähig wegen Tier 1** |
## 4. Tier-1-Fund
### Bosch: vollständige Eliminierung manueller Arbeit ist nicht belegt
Aktuell steht:
> „... ermöglichte damit die automatisierte bildbasierte Defektklassifikation **ohne manuellen Eingriff**.“
`BS-1` belegt eine qualitative Reduktion manueller Klassifikation, ausdrücklich aber keinen genauen Umfang. „Ohne manuellen Eingriff“ behauptet eine vollständige Eliminierung und ist damit stärker als die kanonische Evidenz.
**Sichere Korrekturrichtung:**
> „... ermöglichte damit die automatisierte bildbasierte Defektklassifikation und reduzierte den manuellen Klassifikationsaufwand.“
Das ist der einzige aktuelle Tier-1-Punkt. Nach der Korrektur müssen Validator, Kompilierung, Textextraktion und visuelle PDF-Prüfung erneut laufen.
## 5. Competitive Read
Der offensichtliche Konkurrenzkandidat ist ein Senior Linux-/DevOps-Engineer aus Bund, RUAG, armasuisse oder einem Schweizer ISP: aktuelle Linux-Fleet-Verantwortung, Pull-GitOps, Datacenter-Hardware, mögliche PSP-Erfahrung und Deutsch plus Französisch.
Dennis gewinnt dagegen auf der Verbindung aus Data Platform, Kafka, produktivem Pipeline-Ownership, ML-Inferenzintegration, selbst entwickelten Ansible-Erweiterungen und echter militärischer Biografie. Die Offizierslaufbahn macht die Motivation für Kdo Cy deutlich glaubwürdiger als bei einem rein kommerziell geprägten Bewerber. Der Konkurrenzkandidat bleibt dennoch direkter auf den drei schwächsten Achsen: Datacenter, Pull-GitOps und zweite Amtssprache.
## 6. Reader Sequence
| Leser | Verdict | Wahrscheinlicher Eindruck |
|---|---|---|
| Parser / ATS | **Pass** | Arbeitgeber, Titel, Daten und Kernbegriffe werden sauber extrahiert |
| Recruiter | **Forward** | Staff-Scope, lokale Verfügbarkeit, Deutsch, B-Bewilligung und Offizierslaufbahn ergeben eine plausible Kandidatur |
| Hiring Manager | **Interview** | Bosch plus Swisscom decken den technischen Kern ausreichend; die Bundeswehr-Laufbahn stärkt Motivation und Umfeldfit |
| Technical reviewer | **Interview mit Probeachsen** | Erste Fragen werden aktuelle Linux-Tiefe, Pull-GitOps-Abgrenzung, RZ-Hardware und die tatsächliche Wirkung der ML-Automatisierung betreffen |
Die separate HR-Risikoachse bleibt **Borderline**: Lohnklasse, Engineer-III-Level und mögliche Überqualifikation sind nicht durch Textarbeit lösbar.
## 7. Canonical Claim Audit
| Claim im Paket | Evidenz | Einordnung | Sicher? | Massnahme |
|---|---|---|---|---|
| Über zehn Jahre technische Berufserfahrung | Employment history | Direct | Ja | Keine |
| Sechsjährige Offizierslaufbahn, Lehrgang, Offizierschule, Leutnant | BW-1 | Direct | Ja | Keine Führung, Einsätze, Cyberarbeit oder Clearance ergänzen |
| Swisscom Component Owner mit Betrieb, Datenqualität, Incidents und Pikett | SW-2 | Direct | Ja | Keine |
| Python-Datenanwendungen auf Kubernetes mit GitLab CI/CD | SW-3 | Direct | Ja | Keine |
| Migration der eigenen Domänenpipelines auf AWS | SW-1 | Direct, scoped | Ja | Objekt bleibt auf Fulfillment und Product Analysis begrenzt |
| Data Products und Metadaten im unternehmensweiten Data Mesh | SW-7 | Direct, scoped | Ja | Keine Plattform-/Mesh-Ownership behaupten |
| Linux-Administration und Ansible-Automatisierung bei Bosch | BS-6 | Direct | Ja | Keine Datacenter- oder Fleet-Scale-Zahl ergänzen |
| Ansible-Credential-Plugin mit lokaler Zwischenspeicherung | BS-6 | Direct | Ja | Performance/Skalierbarkeit bleibt qualitativ |
| ML-Inferenzintegration in laufender Halbleiterfertigung | BS-1 | Direct | Teilweise | **„ohne manuellen Eingriff“ entfernen** |
| ELK/Kafka-PoC plus Monitoring/Logging/Alarmierung | BS-4 | Direct-to-Adjacent | Ja | PoC-Scope beibehalten |
| Datenservices und Application-Owner-Verantwortung | BS-2, BS-3 | Direct | Ja | Keine |
| Fraunhofer Microservices und Jenkins-CI/CD | FC-3, FC-1 | Direct | Ja | Keine |
| Vizrt Backend-Komponenten und CI/CD-Quality-Gates | VZ-1, VZ-2 | Direct, komponentenspezifisch | Ja | Keine Kundenlieferung oder Gesamtsystem-Ownership ergänzen |
| Generali BDD- und Jenkins-Verantwortung | GN-1 | Direct | Ja | Keine |
| Privater Debian-Server, Härtung und Dienste | PP-3 | Direct, persönlich | Ja | Persönlichen, nicht betrieblichen Kontext beibehalten |
| Motivation: Rückkehr in ein militärisches Umfeld und Beitrag zum Schutz der Schweiz | Nutzerintention plus BW-1 | Motivation, keine Leistungsbehauptung | Ja | Militärischen Kontext sprachlich präzisieren, siehe Tier 2 |
## 8. Tiered Improvements
### Tier 1
1. Bosch-Bullet von der unbelegten vollständigen Automatisierung auf die belegte Reduktion manueller Klassifikation zurückstufen.
### Tier 2
1. **Kurzprofil komprimieren.** Die Sektorenliste ist weniger wertvoll als die bereits sichtbaren Arbeitgeber und macht aus dem Profil fünf gerenderte Zeilen. Ziel: drei bis vier Zeilen bei Erhalt von Swisscom, Bosch und Bundeswehr. Erwarteter Gewinn: **+0.5 DQ**.
2. **IaC-Formulierung glätten.** „CloudFormation als Infrastructure as Code, IaC“ liest sich technisch korrekt, aber sprachlich konstruiert. Besser: „CloudFormation für Infrastructure as Code (IaC)“. Erwarteter Gewinn: **+0.2 DQ**.
3. **Militärische Motivation präzisieren.** Im Brief „Rückkehr in ein vertrautes Umfeld“ zu „Rückkehr in ein mir vertrautes militärisches Umfeld“ ändern. Das verhindert, dass Bundeswehr und Schweizer Armee als dasselbe Umfeld gelesen werden. Erwarteter Gewinn: **+0.2 DQ**.
### Tier 3
1. Einen der unmittelbar aufeinanderfolgenden `Entwickelte`-Einstiege bei Fraunhofer/Vizrt variieren, ohne den Ownership-Grad zu erhöhen.
2. Die Wiederholung von „wesentlicher Grund“ und „wesentlicher Reiz“ in zwei benachbarten Briefabsätzen glätten.
3. Generali nur dann weiter kürzen, wenn zusätzlicher Platz benötigt wird. Der Eintrag hält die DACH-Chronologie nachvollziehbar und ist nicht schädlich.
## 9. Cover-Letter Decision und Kritik
**Decision: YES.** Das Motivationsschreiben erhöht den Wert des Pakets. Es ergänzt drei Dinge, die der Lebenslauf allein nicht leisten kann: die militärisch begründete Motivation, das persönliche Interesse am gesamten Stack und die praktische Passung mit Region Bern, B-Bewilligung und kurzem Arbeitsweg.
Die technische Argumentation ist spezifisch für diese Stelle und bleibt evidenzsicher. Die Offizierslaufbahn wird weder zu Führungserfolgen noch zu Nachrichtendienst- oder Cybererfahrung aufgeblasen. Das Schreiben ist mit 300 Haupttextwörtern am oberen Rand der Normalspanne, aber auf einer gut lesbaren Seite. Löschen würde das Paket schwächen.
Sprachlich ist der Brief deutlich natürlicher als vor Edit 2. Verbleibend sind nur die Tier-2-Präzisierung des „vertrauten Umfelds“ und kleine Wiederholungen. Keine Em-Dashes, kein generischer Unternehmenslob-Absatz und keine defensive Gap-Liste.
## 10. Mechanical Verification
- Kanonisches System und beide Dokumentvalidatoren: **PASS, 0 Warnungen**
- LaTeX: Lebenslauf **2 Seiten**, Motivationsschreiben **1 Seite**
- Logs: **0 overfull/underfull boxes**, keine LaTeX-Warnungen
- PDF: A4, keine Überlappung, keine abgeschnittenen Zeilen, keine verwaisten Überschriften
- Seitenzahlen: 1/2 und 2/2 vollständig innerhalb der Seitenkoordinaten
- `pdftotext -layout`: Arbeitgeber, Titel, Orte und Zeiträume in korrekter Reihenfolge
- Visuelle Prüfung: alle drei Seiten vollständig kontrolliert; Hierarchie, Abstände und Lesbarkeit sauber
- Unicode-Prüfung: keine En-, Em- oder geschützten Dashes in den Quellen; LaTeX-Doppelhyphen nur für Datumsbereiche
- AI-Fingerprint: keine auffälligen Gedankenstrichmuster oder generische Firmensprache; leichte Listen- und Verbkadenz bleibt ein kleiner Stilpunkt
## Schlussurteil
**Rollenfit:** 79/100, Core, Hard Gate PASS.
**Dokumentqualität:** 92/100.
**Channel:** Weak.
Die inhaltliche Positionierung ist jetzt deutlich stärker: Die Bundeswehr-Laufbahn ist an den beiden richtigen Stellen sichtbar und bleibt zugleich beweissicher. Vor einer Einreichung ist genau ein inhaltlicher Fix erforderlich, danach sind nur noch optionale Tier-2-Politur und die telefonische Klärung von Lohnklasse und Level offen.
@@ -0,0 +1,55 @@
% Kdo Cy: DevOps Engineer III (Data Platform). German-language Swiss/DACH letter.
% Every claim traces to a resume bullet and a canonical ID. The second-Amtssprache point is
% deliberately NOT raised: the user confirmed it is not a hard requirement, so naming it here
% would hand the reader an objection, which was the Aker BP CL-A finding.
\documentclass[11pt,a4paper]{article}
\usepackage[utf8]{inputenc}
\usepackage[T1]{fontenc}
\usepackage[ngerman]{babel}
\usepackage{lmodern}
\usepackage[a4paper,left=0.85in,right=0.85in,top=0.7in,bottom=0.7in]{geometry}
\usepackage{parskip}
\usepackage{xcolor}
\usepackage{hyperref}
\hypersetup{hidelinks}
\pagestyle{empty}
\setlength{\parindent}{0pt}
\begin{document}
{\Large\bfseries Dennis Thiessen, M.Eng.}\par
Bern, Schweiz $\vert$
\href{mailto:dennis@thiessen.io}{dennis@thiessen.io} $\vert$ +41 795 955 585 $\vert$
\href{https://linkedin.com/in/dennis-thiessen}{LinkedIn}
\vspace{1.5em}
Schweizer Armee, Kommando Cyber\\
Herr Marcel Matthey-Doret\\
Eichacher, 3086 Wald
\vspace{1em}
\today
\vspace{1em}
\textbf{Bewerbung als DevOps Engineer III (Data Platform), Ref. JRQ\$540-19848}
\vspace{0.8em}
Sehr geehrter Herr Matthey-Doret
Ihre Ausschreibung verbindet zwei Aufgaben, die mich fachlich besonders interessieren: den Betrieb einer Datenplattform mit MLOps-Umgebungen bis zur GPGPU-Hardware und die Administration der darunterliegenden Linux-Systeme. Bei Bosch arbeitete ich genau an dieser Schnittstelle. In der durchgehend laufenden Halbleiterfertigung waren robuste Automatisierung und klare Betriebsabläufe Voraussetzung. Dort integrierte ich containerisierte ML-Inferenz und administrierte die Linux-Systeme für die zugehörigen Workloads.
Die Infrastrukturautomatisierung habe ich bei Bosch nicht nur eingesetzt, sondern erweitert. Die Ansible-Playbooks lagen in Git und wurden über Jenkins- und GitLab-Pipelines ausgeführt. Für wiederkehrende Engpässe entwickelte ich eigene Ansible-Erweiterungen, darunter ein Plugin, das Zugangsdaten aus einem Passwort-Keystore lokal zwischenspeichert und dadurch wiederholte Abrufe reduziert. Heute verantworte ich bei Swisscom als Component Owner geschäftskritische Datenstrecken mit Oracle, Kafka und Teradata, einschliesslich Pikettdienst und Datenqualität. Für mich gehört der Betrieb damit zur Entwicklung: Erst im laufenden Einsatz zeigt sich, ob eine Plattform trägt.
Die Aufgabe hat für mich auch persönlich Gewicht. Ich diente sechs Jahre in der Bundeswehr, absolvierte den Offizieranwärterlehrgang und die Offizierschule und schied als Leutnant aus. Für die Schweizer Armee zu arbeiten wäre für mich eine Rückkehr in ein vertrautes Umfeld, nun mit meiner technischen Berufserfahrung. Zum Schutz der Schweiz und ihrer Bevölkerung beizutragen, ist ein wesentlicher Grund für meine Bewerbung.
Die Arbeit über den gesamten Stack bis in den Serverraum ist für mich ein wesentlicher Reiz der Stelle. Seit rund zehn Jahren betreibe ich einen eigenen Debian-Server mit nginx, Mailserver, VPN und Docker-Diensten, samt Härtung und Updates, weil mich diese Arbeit interessiert. Ich bin deutscher Staatsangehöriger mit Schweizer B-Bewilligung. Deutsch ist meine Muttersprache, und ich lebe in der Region Bern. Zimmerwald wäre für mich ein kurzer Arbeitsweg und eine langfristige Perspektive.
Ich freue mich auf die Gelegenheit zu einem Gespräch und darauf, mehr über die Rolle der Plattform im Zielbild Ihres Teams zu erfahren.
Freundliche Grüsse
\vspace{1.5em}
Dennis Thiessen
\end{document}
@@ -0,0 +1,93 @@
% Kommando Cyber (Kdo Cy): DevOps Engineer III (Data Platform), Zimmerwald
% German-language Swiss/DACH profile. Position titles stay English (user decision 2026-08-27).
% Generated from claims.json only. New evidence this round: BS-6 (Linux estate + Ansible
% extensions) and PP-3 (self-hosted Debian). The pull-reconciliation buzzword the JD uses is
% forbidden by claims.json because execution was push-based from Jenkins/GitLab, so the Bosch bullet
% states the mechanism literally instead.
\documentclass{resume}
\usepackage[utf8]{inputenc}
\usepackage[T1]{fontenc}
\usepackage[ngerman]{babel}
\usepackage{lmodern}
\usepackage[a4paper,left=0.65in,right=0.65in,top=0.55in,bottom=0.55in]{geometry}
\usepackage{xcolor}
\usepackage{hyperref}
\hypersetup{hidelinks}
\usepackage[version=4]{mhchem}
\usepackage{fancyhdr}
\pagestyle{fancy}
\fancyhf{}
\renewcommand{\headrulewidth}{0pt}
\fancyfoot[R]{\small \thepage/\pageref{LastPage}}
\name{Dennis Thiessen, M.Eng.}
\headline{Staff Data \& Platform Engineer $\vert$ Linux, Ansible, Kubernetes $\vert$ Datenplattformen, Produktionsbetrieb und ML-Deployment}
\contactline{Bern, Schweiz $\vert$ \href{mailto:dennis@thiessen.io}{dennis@thiessen.io} $\vert$ +41 795 955 585 $\vert$ \href{https://linkedin.com/in/dennis-thiessen}{LinkedIn}}
\begin{document}
\begin{rSection}{Kurzprofil}
Staff Engineer mit über zehn Jahren technischer Berufserfahrung in Telekommunikation, Halbleiterfertigung, Broadcast-Technologie und Versicherung sowie sechsjähriger Offizierslaufbahn bei der Bundeswehr. Verantwortet bei Swisscom geschäftskritische Datenstrecken und Kubernetes-Anwendungen im Produktivbetrieb. Administrierte und automatisierte zuvor bei Bosch Linux-Systeme für Analyse- und ML-Workloads und integrierte dort containerisierte ML-Inferenz in eine durchgehend laufende Halbleiterfertigung.
\end{rSection}
\begin{rSection}{Kenntnisse}
\skillline{Programmiersprachen}{Python, SQL; Java und C\# aus früheren beruflichen Projekten}
\skillline{Linux und Automatisierung}{Linux-Administration (Bosch), Systemhärtung (laufender Eigenbetrieb), Ansible einschliesslich eigener Erweiterungen, Jenkins, GitLab CI/CD, CloudFormation (IaC)}
\skillline{Container, Cloud und MLOps}{Docker, Kubernetes, Microservices, MLOps (Deployment und Orchestrierung containerisierter ML-Inferenz), AWS (S3, Glue, Athena/Iceberg, Redshift)}
\skillline{Daten und Observability}{Apache Kafka, Airflow, PySpark, Oracle, Teradata, Hadoop/Impala, Data Products und Metadaten; ELK, Grafana, Prometheus, Loki}
\skillline{Zertifizierungen}{AWS Certified Solutions Architect (Associate); Data Engineering with AWS; iSAQB CPSA-F; ITIL Foundation}
\skillline{Sprachen}{Deutsch (Muttersprache), Englisch (fliessend), Norwegisch und Russisch (Grundkenntnisse)}
\end{rSection}
\begin{rSection}{Berufserfahrung}
\begin{rSubsection}{Swisscom (Schweiz) AG}{Okt. 2023 -- heute}{Staff Data, Analytics \& AI Engineer (seit Apr. 2025; zuvor Senior)}{Bern, Schweiz}
\item Verantworte als Component Owner geschäftskritische ETL-Strecken der Fulfillment-Domäne mit Oracle, Kafka, Python und Teradata, einschliesslich Produktivbetrieb, Datenqualität, Governance, Störungsbearbeitung und Pikettdienst.
\item Entwickle und betreibe Python-Datenanwendungen auf Kubernetes mit GitLab CI/CD, vom Container-Build über das Deployment bis zum laufenden Betrieb.
\item Migrierte die Pipelines der Domänen Fulfillment und Product Analysis auf die AWS-Plattform (Glue, Athena mit Apache Iceberg, Redshift, Airflow und CloudFormation als Infrastructure as Code, IaC) und unterstützte damit das übergreifende Migrationsprogramm.
\item Modelliere governance-konforme Data Products und pflege deren aktive Metadaten im unternehmensweiten Data Mesh, damit nachgelagerte Teams die Daten auffinden und einordnen können.
\end{rSubsection}
\begin{rSubsection}{Robert Bosch Semiconductor Manufacturing Dresden GmbH}{Feb. 2020 -- Dez. 2022}{Senior Engineer, Data Analysis (Data \& ML Engineering)}{Dresden, Deutschland}
\item Integrierte containerisierte ML-Inferenz mit Docker, Kubernetes und Ansible in eine durchgehend laufende Halbleiterfertigung und ermöglichte damit die automatisierte bildbasierte Defektklassifikation ohne manuellen Eingriff.
\item Administrierte und automatisierte die Linux-Serverlandschaft für Analyse- und ML-Workloads, darunter ML-Plattform, Docker-Hosts, Backend-Dienste und Ansible-Steuerung. Die Playbooks lagen in Git und wurden über Jenkins- und GitLab-Pipelines ausgeführt.
\item Erweiterte Ansible unter anderem um ein Plugin für Zugangsdaten, das Secrets aus einem Passwort-Keystore abruft und lokal zwischenspeichert. Dies reduzierte wiederholte Keystore-Abfragen und verbesserte Performance und Skalierbarkeit.
\item Implementierte einen Proof of Concept zur Anomalieerkennung mit ELK, Kafka und Docker sowie Monitoring, Logging und Alarmierung mit Grafana, Prometheus und Loki.
\item Entwickelte Datenservices in Python, Java und C\# auf Basis von Oracle und Hadoop/Impala für Defect Management und Prozessanalyse.
\item Verantwortete als Application Owner Analyseanwendungen und vorgelagerte Pipelines, einschliesslich SLOs, Anwenderschulung, technischer Dokumentation und Abstimmung mit Lieferanten.
\end{rSubsection}
\begin{rSubsection}{Fraunhofer CML}{Sep. 2018 -- Okt. 2019}{Research Software Engineer}{Hamburg, Deutschland}
\item Entwickelte containerisierte Microservices für eine maritime Forschungsplattform und führte eigenständig eine Jenkins-CI/CD-Strecke mit Quality Gates ein.
\end{rSubsection}
\begin{rSubsection}{Vizrt}{Jul. 2017 -- Mai 2018}{Test Automation / DevOps Engineer}{Bergen, Norwegen}
\item Entwickelte Python- und C++-Backend-Komponenten für ein verteiltes Video-Transcoding-System. Integrierte automatisierte Audio-/Video-Tests als Quality Gates in die CI/CD-Pipeline.
\end{rSubsection}
\begin{rSubsection}{Generali Deutschland Informatik Services GmbH}{Mai 2015 -- Jun. 2017}{IT Consultant}{Hamburg, Deutschland}
\item Führte BDD-Testautomatisierung mit einem Proof of Concept ein und übernahm die technische Verantwortung für Testsuite und Jenkins-Jobs.
\end{rSubsection}
\begin{rSubsection}{Bundeswehr}{Juli 2008 -- Nov. 2014}{Offizieranwärter und Offizier (zuletzt Leutnant)}{Deutschland}
\item Diente sechs Jahre in der Bundeswehr, absolvierte den Offizieranwärterlehrgang und die Offizierschule und schied als Leutnant aus.
\end{rSubsection}
\end{rSection}
\begin{rSection}{Projekte}
\begin{rSubsection}{Privater Debian-Server}{seit rund zehn Jahren}{Eigenbetrieb}{}
\item Betreibe und administriere einen selbst gehosteten Debian-Server mit nginx, Mailserver, Nextcloud, VPN, Docker-Diensten und Bitwarden, inklusive Systemhärtung und Security-Konfiguration.
\end{rSubsection}
\end{rSection}
\begin{rSection}{Ausbildung}
\compactentry{M.Eng. Computer Aided Engineering}{Apr. 2012 -- Okt. 2013}
Universität der Bundeswehr München, Schwerpunkt Software Design \& Engineering. Masterarbeit an der Tongji-Universität, Shanghai: \textit{Development of a Web-Based Remote Fault Diagnosis System}.
\compactentry{B.Eng. Information and Telecommunication Technologies}{Okt. 2009 -- Okt. 2012}
Universität der Bundeswehr München.
\end{rSection}
\end{document}
@@ -0,0 +1,59 @@
\ProvidesClass{resume}[2026/07/27 Evidence-first professional resume]
\LoadClass[11pt,a4paper]{article}
\RequirePackage{enumitem}
\RequirePackage{ifthen}
\RequirePackage{lastpage}
\RequirePackage{parskip}
\RequirePackage{needspace}
\pagestyle{empty}
\setlength{\parindent}{0pt}
\def\@resumename{}
\def\@resumeheadline{}
\def\@resumecontact{}
\newcommand{\name}[1]{\def\@resumename{#1}}
\newcommand{\headline}[1]{\def\@resumeheadline{#1}}
\newcommand{\contactline}[1]{\def\@resumecontact{#1}}
\newcommand{\printresumeheader}{%
{\LARGE\bfseries \@resumename}\par
\vspace{0.15em}
\ifthenelse{\equal{\@resumeheadline}{}}{}{\@resumeheadline\par}
\vspace{0.1em}
{\small \@resumecontact}\par
\vspace{0.45em}
}
\AtBeginDocument{\printresumeheader}
\newenvironment{rSection}[1]{%
\vspace{0.35em}
{\bfseries #1}\par
\vspace{0.1em}\hrule\vspace{0.35em}
}{%
\vspace{0.2em}
}
% Arguments: employer, dates, formal title, location.
\newenvironment{rSubsection}[4]{%
\Needspace{6\baselineskip}%
{\bfseries #1}\hfill{\small #2}\par
{\itshape #3}\hfill{\itshape #4}\par
\vspace{0.1em}
\begin{itemize}[leftmargin=1.25em,label=\textbullet,itemsep=0.18em,topsep=0.15em,parsep=0pt,partopsep=0pt]
}{%
\end{itemize}
\vspace{0.25em}
}
\newcommand{\skillline}[2]{%
\textbf{#1:} #2\par
\vspace{0.08em}
}
\newcommand{\compactentry}[2]{%
\textbf{#1}\hfill #2\par
}
@@ -0,0 +1,278 @@
# Session: Schweizer Armee — Kommando Cyber (Kdo Cy) — DevOps Engineer III (Data Platform)
## JD Integrity
- **File/source:** `JD_kdocy_devops_data_platform.txt` (this folder) — verbatim body of `https://jobs.admin.ch/offene-stellen/devops-engineer-iii-data-platform/752ded37-1753-4ac8-946a-b0c958d4424a`
- **Retrieval method and date:** direct HTTP fetch of the Prospective-ATS detail page, HTML stripped, **2026-08-27**. Not reconstructed, not paraphrased.
- **Verbatim posting:** YES
- **Posting status:** LIVE 2026-08-27. Confirmed present in the portal's own `Kdo Cy` search result set the same day (11 Kdo Cy roles open).
- **Source of the lead:** user, manually — `jobs.admin.ch` is **not** in the job_scout roster.
## JD Info
| Field | Value |
|---|---|
| Employer | Schweizer Armee — Kommando Cyber (Kdo Cy) |
| Role | DevOps Engineer III (Data Platform) |
| Reference | JRQ$540-19848 |
| Arbeitsort | **Eichacher, 3086 Wald (Zimmerwald)** |
| Pensum | 80100%, Jobsharing möglich |
| Anstellungsart | unbefristet |
| Eintritt | nach Vereinbarung |
| Deadline | none stated |
| Contact | **Marcel Matthey-Doret, Chef Centers of Excellence CEA, +41 58 46 78409** |
| Language of posting | German |
## Application Decision
- **Audience profile:** Swiss/DACH (German-language federal employer, German-language posting)
- **Evidence Fit: 79/100 — Core (lower end)**. Trajectory, all on 2026-08-27: **55** as posted → **64** after the language/citizenship answers → **68** after the Ansible correction → **79** after the Linux-administration and Ansible-extension evidence. **The movement is KB repair, not re-framing** — two canonical blind spots (Ansible, Linux) were suppressing a real profile.
- **Fit class: Core** (lower end, 75+)
- **Hard gate: PASS.** All three original §1 triggers now cleared — see Gate Audit. Remaining honest weakness is **physical datacenter work (R6), a genuine Gap** that interest does not substitute for.
- **Channel Strength:** Weak today; **upgradeable to Moderate** — the posting publishes a named contact with a direct number
- **Channel plan:** phone Matthey-Doret **before** any document work — the same call resolves both gates
- **Cohort slot:** recorded on submission in evidence-first-2026-01, now **5/10 applications and Core 3/7**. Adjacent remains 2/2 and Stretch 0/1.
- **Decision: SUBMITTED 2026-08-27.** Evidence Fit 79/Core, hard gate PASS, Document Quality 92, channel Weak.
## Gate Audit (`critique_framework.md` §1)
**UPDATED 2026-08-27 — user-confirmed that neither the second Amtssprache nor Swiss citizenship is a hard requirement.** Two of three triggers cleared; one stands.
-**CLEARED — second Amtssprache.** Confirmed a Wunschkriterium, not a filter. It stays a competitive disadvantage against a candidate who has French, and it is a plausible interview topic, but it no longer gates the application.
-**CLEARED — citizenship.** A German citizen with a B permit is eligible. The PSP itself still happens; its level and timing are simply not disqualifying facts.
-**CLEARED 2026-08-27 — the title-defining capability.** This was called a Gap on an incomplete KB. It was wrong. The role runs the Linux/IKT layer beneath a data platform, and the user in fact has: **~3 years of professional Linux estate administration and automation at Bosch** (ML platform hosts, Docker hosts, backend services, Ansible control — BS-6), **Ansible extension development** (a credential plugin with local caching to cut keystore lookups — infrastructure engineering, not tool usage), and **~10 years of continuous self-hosted Debian administration and hardening** (PP-3). The operating layer is **Adjacent-to-Direct**, not a Gap.
- ⚠️ **REMAINING, and not to be papered over — R6 physical datacenter work.** Zero experience. The user states genuine interest, which honestly addresses the JD's *"Freude an der Arbeit über den gesamten Stack"* criterion — but interest is not experience, and the resume must not imply otherwise. This belongs in the cover letter as motivation, never in a bullet as evidence.
### Original audit, retained for the record
Three of the four NO-GO triggers fired as posted:
1. **A required qualification is a Gap***"Aktive Kenntnisse einer zweiten Amtssprache"*. German is his native tongue and is itself an Amtssprache; the requirement is for a **second** one (French, Italian, Romansh). `claims.json` `identity.languages` = German native, English fluent, **Norwegian basic, Russian basic**. Neither is an Amtssprache. There is no bridge and nothing to write around. **Note:** `config.md` records that the Swisscom Zeugnis lists French and Italian as HR boilerplate and that this is **explicitly forbidden** on any document — so the one place those languages appear on paper is a known falsehood and must not be used here of all places.
2. **The title-defining capability is not Direct** — the title is *DevOps Engineer (Data Platform)*, and the function as written is running the **IKT/Linux layer beneath** a data platform: whole-system Linux administration, performance tuning, hardening, plus physical datacenter duty. Dennis builds and owns **data products and pipelines on top of** managed platforms. Same authoring-vs-operating split as Aker BP, one layer lower.
3. **Clearance is unresolved** — the posting requires the ability to integrate into a *nachrichtendienstliches Umfeld*, is silent on nationality, and he is a German citizen. Unresolved either way.
## Requirements
| # | Requirement (verbatim sense) | Req/Pref | Class | Canonical evidence | Gate? |
|---|---|---|---|---|---|
| Q1 | IT-Abschluss HF/FH + mehrere Jahre Praxis im Engineering und Betrieb komplexer IT-Systeme | Required | **Direct** | EDU-MENG (M.Eng., exceeds HF/FH); ~13 yrs across SWISSCOM/BOSCH/FRAUNHOFER/VIZRT | — |
| Q2 | Fundierte DevOps-Kompetenz: Aufbau/Betrieb/Automatisierung **moderner Linux-Infrastrukturen**, umfassende Kenntnisse **IaC und GitOps** | Required | **Adjacent, upgraded 2026-08-27** | **IaC is Direct:** intensive Ansible work at Bosch plus production-current CloudFormation. **Linux administration is Direct via BS-6** and current personal hardening is PP-3. GitOps was clarified as Git-versioned, push-executed automation without a reconciliation agent; the named practice remains a Gap and the word stays forbidden. | ⚠ |
| Q3 | Lernbereitschaft, Offenheit für Nicht-Mainstream-Ansätze (Dhall, Pull-GitOps, Dew-/Fog-Computing) | Required (attitude) | **Neutral** | Attitude criterion; the named technologies are exotic and no candidate will hold them | — |
| Q4 | Hands-on über den ganzen Stack — **von physischer Infrastruktur im Rechenzentrum** bis Big-Data-Umgebungen **wie ClickHouse und Kafka** | Required | **Split** | **Kafka Direct** (production-current). ClickHouse: Gap but substitutable — BS-2 Oracle + Hadoop/Impala, SQL production-current. **Physical DC/server/network hardware: Gap, 0 evidence** | ⚠ |
| Q5 | Tadelloser Leumund + Fähigkeit, sich in ein **nachrichtendienstliches Umfeld** zu integrieren — *"werden vorausgesetzt"* | Required | **Constraint — RESOLVED 2026-08-27** | Swiss citizenship confirmed not a hard requirement (user). German citizen + B permit is eligible; a PSP still runs | ✅ |
| Q6 | **Aktive Kenntnisse einer zweiten Amtssprache** + gute Englischkenntnisse | Required | **Soft — RESOLVED 2026-08-27** | Confirmed not a hard requirement (user). English half Direct. Remains a competitive disadvantage and a likely interview question | ✅ |
| R1 | IaC/GitOps planen, implementieren, betreiben; ganzen Deployment-Zyklus verantworten | Core resp. | **Adjacent** | SW-3, FC-1, VZ-2, CloudFormation and BS-6. The Ansible flow was version-controlled and CI-driven but push-based, not Pull-GitOps. | — |
| R2 | **MLOps-Umgebungen** für Deployment, Monitoring, Betrieb von KI-/ML-Modellen **bis zur GPGPU-Hardware** | Core resp. | **Adjacent — strongest hook** | BS-1 (containerized ML inference integrated into a 24/7 semiconductor production environment) + SW-3. **GPGPU: Gap.** BS-1 forbids claiming model training or full-lifecycle ownership | — |
| R3 | Komplexe **Linux-Systemlandschaften** für den E2E-Betrieb der IKT-Schicht einer **Datenplattform** | Core resp. | **Adjacent-to-Direct** | Data-platform operation is Direct through SW-1, SW-2 and SW-7; professional Linux-estate administration and automation is Direct through BS-6. The two layers are proven in different roles rather than as one current end-to-end platform. | — |
| R4 | Linux ganzheitlich administrieren, Performance-Optimierung, **System-Hardening**, Security-Konfigurationen | Core resp. | **Adjacent-to-Direct — upgraded 2026-08-27** | **BS-6** (Bosch Linux estate: ML platform, Docker hosts, backend, Ansible control) + **PP-3** (~10 yrs self-hosted Debian: nginx, mail, Nextcloud, VPN, Docker, Bitwarden — administered and hardened). **Hardening evidence leans personal — state it as such**, never imply an employer mandate | — |
| R5 | Monitoring-, Logging-, Observability-Lösungen betreiben und weiterentwickeln | Core resp. | **Direct-to-Adjacent** | BS-4 (ELK/Kafka anomaly-detection PoC + monitoring) — scoped as a PoC, **never** an enterprise observability platform | — |
| R6 | Physische Infrastruktur im Rechenzentrum betreuen, Installationen und Wartung unterstützen | Core resp. | **Gap — remains** | 0 experience. User states genuine interest, which answers Q4's *Freude*-criterion honestly. **Cover letter as motivation; never a resume bullet** | ⚠ |
## Evidence Fit Breakdown
| Dimension | Weight | Score | Reasoning |
|---|---:|---:|---|
| Required qualifications | 35 | **30** | Q1 Direct, Q3 neutral, English Direct, **Q5 and Q6 resolved 2026-08-27**; Q4 remains split (physical DC absent); **Q2 improved — IaC is now Direct via Ansible + CloudFormation**, GitOps-as-practice and Linux depth still thin |
| Core responsibilities | 25 | **19** | R2/R3/R4/R5 are Direct-to-Adjacent and R1 is Adjacent; **R6 physical datacenter work remains a Gap**. GPGPU and Pull-GitOps also remain unevidenced. |
| Level and ownership | 15 | **10** | Engineer III vs current Staff/Engineer IV; Component Owner and Application Owner scope (SW-2, BS-3) comfortably covers the ownership asked. Reads lateral-to-slightly-below |
| Recency and depth | 10 | **9** | Kubernetes, Kafka, Python, SQL, CI/CD all production-current. BS-1/BS-4 are the strongest role-specific proofs but date to Bosch, not today |
| Domain/tool transfer | 10 | **7** | ClickHouse ← Impala/Oracle/SQL: yes. Git-versioned CI/CD automation transfers partly to GitOps concepts but is not Pull-GitOps. **Physical datacenter hardware and GPGPU are not substitutable.** Linux administration and hardening are now directly evidenced through BS-6 and PP-3. |
| Practical constraints | 5 | **4** | Best commute in the entire log, unbefristet, 80100%, language and citizenship both cleared. Held back only by **comp — the Lohnklasse is still unknown** |
| **Total** | | **79** | **Core (lower end)** — 55 → 64 → 68 → **79**, every step a KB correction rather than a re-framing |
**Current fit state after the full 2026-08-27 KB repair:** language and citizenship constraints are cleared, and Linux/IKT operation is now evidenced through BS-6 plus PP-3. The remaining evidence gaps are physical datacenter work, Pull-GitOps, GPGPU and ClickHouse by name. The resulting score is 79/Core.
**Still open and unasked: compensation.** Bund Lohnklasse for a DevOps Engineer III is not public and must be asked, not researched — the same class as the SBB Anforderungsniveau K. Current comp is ~140k; the local tier permits near-current, not a steep cut.
## ATS Keywords
- **Direct, usable:** DevOps, CI/CD, GitLab CI/CD, Kubernetes, Docker, Container, Kafka, Python, SQL, Datenplattform, Data Platform, Data Pipelines, Monitoring, Logging, Observability, ELK, Automatisierung, Infrastructure as Code, CloudFormation, Deployment, AWS
- **Bridge, use with care:** MLOps, ML-Inferenz im Produktivbetrieb, Betrieb 24/7, Datenqualität, Governance, On-Call, Incident
- **Gap — do NOT seed:** GitOps, Dhall, Pull-GitOps, Dew-/Fog-Computing, ClickHouse, GPGPU, Rechenzentrumsbetrieb, Terraform, Zero Trust
- **Forbidden here by `claims.json`/`config.md`:** French, Italian (Zeugnis boilerplate — a known falsehood), LangChain/LangGraph/LlamaIndex, Azure, GCP, Terraform, "built the observability platform", "own the data platform"
## Gap Assessment
1. **Physical datacenter work** — zero experience and a genuine downward-scope signal for someone at Staff level.
2. **Pull-GitOps as a named practice** — the real flow was Git-versioned but push-executed from Jenkins/GitLab without a reconciliation agent.
3. **ClickHouse and GPGPU** — Impala/Oracle/SQL and containerized inference provide honest bridges, not Direct evidence.
4. **Second Amtssprache** — confirmed as a soft criterion rather than a hard gate; still a competitive disadvantage.
5. **PSP** — eligibility is cleared, but no present or former clearance is claimed and the normal screening process remains.
6. **Level and compensation** — Engineer III may be lateral or slightly below current Staff scope; Lohnklasse remains unknown.
## Company Context
- **Kommando Cyber (Kdo Cy)** — stood up **1 Jan 2024** as the Army's cyber/ICT command; ~9,000 civilian and military staff across the Army, Kdo Cy itself being the ICT and cyber-defence arm for the Army and the Sicherheitsverbund Schweiz.
- **Neue Digitalisierungsplattform (NDP)** — Kdo Cy's flagship programme: a secure, robust, resilient platform as the technical foundation for digitising the Army, consolidating today's decentralised datacenter infrastructure; first services expected from **July 2026**. This role's "Datenplattform" sits in that world and is the single best-informed thing to raise on the call.
- **Zimmerwald is the Zentrum elektronische Operationen (ZEO).** This is the Army's SIGINT evaluation site: intercepted satellite and cable communications collected elsewhere are evaluated there, and Comint reporting goes to the NDB. That is exactly what the JD's *"erfasste zivile und militärische Kommunikationsdaten … Erkenntnisse unterstützen den NDB und den MND"* describes.
- **Material implication for the user, not just for the documents:** this is an intelligence job, not a corporate platform job. It carries a clearance process, standing public and parliamentary scrutiny of Funk-/Kabelaufklärung, and a career narrative that is harder to reverse than a normal move. Worth wanting deliberately.
## Level Read — user raised overqualification 2026-08-27
**Question:** the JD asks only for *"Abgeschlossene Ausbildung im IT-Bereich HF/FH"*, not a university degree — is the seat below his level?
- **The education line is the weakest of the level signals.** Swiss postings state a *minimum*; exceeding it is routine and nobody is filtered out for holding an M.Eng. Do not read the band off this line.
- **"III" is Senior, and that is primary-source, not inference.** The same unit's parallel posting on the same portal reads **"ICT-Architekt/-in III (Senior ICT Systems Architect)"** — Kdo Cy glosses its own roman numeral as Senior. So III is not a junior band.
- **The responsibility language is nonetheless practitioner-level.** The role is *"fachlich mitverantwortlich"* — shared technical responsibility, not lead. No people leadership, no architecture ownership, and it carries **physical datacenter installation and maintenance support**. Against his current Staff/Engineer IV plus Component Owner (SW-2) and prior Application Owner (BS-3) scope, this reads **lateral at best, plausibly a half-step down**.
- **Same shape as two known cases:** BKW was **declined** on exactly this (lateral, no upside), and SBB was flagged *"lateral or below"* and submitted anyway. `user_role_targeting_energy_trading` records the standing rule: no lateral same-tier moves. The Bern/Thun local tier is the deliberate exception, and it is what this role trades on.
- **The sharper risk is the mirror image: being screened out as overqualified.** Public-sector HR does filter for this, particularly when a Lohnklasse cannot match current comp. That makes the pay question do double duty — it is both his decision input and their objection.
- **The posting names no Lohnklasse** (0 hits). Federal pay classes exist publicly, but which class this seat sits in is not stated and must be asked, not assumed — same discipline as the SBB Anforderungsniveau K.
- **No better-levelled technical seat exists at Kdo Cy today.** Of the 11 open roles, the alternatives are PM/portfolio track (Portfolio-Manager, Senior Projektleiter, Projektmanagement Officer — not his lane) or ICT-Architekt III, which is nominally higher but a worse content fit (network/security architecture) and carries a harder language bar (second Amtssprache *plus* a passive third).
**Post-submission option:** a concise call to Matthey-Doret could still clarify Lohnklasse/band, how Engineer III is levelled and the development path for someone arriving at Staff scope. No such conversation is recorded, so channel strength remains Weak.
## Competitive Read
- **Obvious-fit candidate:** a Swiss-national senior Linux/DevOps engineer out of a Bund contractor, RUAG, armasuisse or a Swiss ISP — Linux fleet operations in the bones, IaC/GitOps daily, holds or has held a PSP, speaks German plus French, and is comfortable in a rack.
- **Dennis's advantage:** the **data side**. Real Kafka in production, governed data products, pipeline ownership with SLOs and on-call (SW-2), containerized ML inference put into a 24/7 production environment (BS-1), ELK/Kafka anomaly detection (BS-4). A Linux/DevOps generalist will not have built the platform's *data* half. Plus native German, EU/B-permit work authorisation, and he lives ~a village away.
- **Their advantage:** they are Direct on the exact axis the title names — Linux, hardening, GitOps, datacenter — they clear the language requirement without a conversation, and their clearance path is uncomplicated.
- **Level/scope:** Engineer III against his Staff/Engineer IV. Not a step up.
## Framing Strategy *(only if the call clears the gates)*
- **Professional identity:** Staff Data & Platform Engineer who builds and operates production data platforms — containers, CI/CD, streaming, observability — and has taken ML inference into 24/7 production.
- **Lead narrative:** the data platform's operating half, not the rack's.
- **Strongest proof points:** SW-2 (Component Owner, business-critical ETL with data quality, governance, incidents, on-call), SW-3 (Python applications on Kubernetes with GitLab CI/CD), BS-1 (containerized ML inference into 24/7 semiconductor production — the honest MLOps hook), BS-4 (ELK/Kafka anomaly detection and monitoring), SW-7 (governed data products, scoped **inside** the company-wide Data Mesh — never as owner), Kafka.
- **Honest bridges:** IaC via **CloudFormation**, never implied as Terraform. GitOps approached from GitLab CI/CD, named as adjacent rather than held. ClickHouse approached from Oracle/Impala/SQL.
- **Explicit gaps to state rather than paper over:** physical datacenter work, Pull-GitOps as a practice, GPGPU and ClickHouse by name.
- **Scope Discipline watch:** SW-1 must stay scoped to his own domains' pipelines; SW-7 must never read as owning the Mesh; BS-4 must never become "the observability platform".
- **User directives:** include the Bundeswehr officer career as the defence-role USP; explain the motivation to return to a military environment and contribute to protecting Switzerland and its population; remove em-dash punctuation; remove awkward German; omit C++/JavaScript from the skills block.
- **GitOps clarification resolved:** playbooks lived in Git and were applied push-style from Jenkins/GitLab. No reconciliation agent was present. The word stays forbidden; describe the mechanism literally.
## Bullet Plan — Phase 1 (proposed 2026-08-27, awaiting confirmation)
**Confirmed by user 2026-08-27:** documents in **German**; bundle **ML/MLOps primary + Data Engineer secondary**; format 2-page Swiss/DACH.
Budget per `config.md`: **1114 bullets**. Recommended set = **10**, leaving 14 discretionary slots.
### Swisscom — Staff Data, Analytics & AI Engineer (Oct 2023 heute)
| | ID | Achievement | JD hook | Match |
|---|---|---|---|---|
| * | SW-3 | Python-Anwendungen auf Kubernetes, GitLab CI/CD, voller Deployment-Zyklus | R1 Deployment-Zyklus, Q2 DevOps | Direct |
| * | SW-2 | Component Owner, Oracle/**Kafka** → Teradata, Pikett, SLA, Data Governance | Q4 Kafka, R3 Betrieb, "tadelloser" Betriebsnachweis | Direct |
| * | SW-1 | Migration der eigenen Domänen auf AWS, **CloudFormation = IaC** (scope-corrected: seine Domänen, nie "die" Migration) | Q2 IaC | Direct (IaC) / Adjacent (rest) |
| * | SW-7 | Governed Data Products + aktives Metadatenmanagement im unternehmensweiten Data Mesh | R3 Datenplattform | Adjacent |
| o | SW-8 | Domänen-gegroundete LLM-Agenten (Modellauswahl + Wissensbasis) | R2 KI-Modelle — but configuration, not MLOps | Bridge |
| o | SW-5 | Security Champion 2025/2026 | R4 System-Hardening/Security-Konfigurationen — the JD *does* name security, which is the `config.md` trigger. Rotating team role, weak signal | Weak |
| x | SW-4 | B2B-Datenprodukte, Dashboards | wrong axis for an operating role | — |
| — | SW-6 | PySpark | fold into Skills, not a bullet | — |
### Bosch Halbleiterwerk Dresden — Data & ML Engineer (Feb 2020 Dez 2022)
| | ID | Achievement | JD hook | Match |
|---|---|---|---|---|
| * | BS-1 | Containerisierte ML-Inferenz (Docker, Kubernetes, **Ansible**) in 24/7-Halbleiterfertigung | **R2 MLOps — the anchor bullet**, plus Q2 IaC via Ansible | Direct-to-Adjacent, strongest |
| * | BS-4 | Anomalieerkennung mit ELK + Kafka, Grafana/Prometheus/Loki | **R5 Observability — direct hit**; Kafka again | Direct |
| * | BS-2 | Datenservices über OracleDB und Hadoop/ImpalaSQL | **Q4 ClickHouse bridge** (columnar/Big-Data analytics store) | Bridge |
| * | BS-3 | Application Owner: SLOs, Schulung, Dokumentation, Vendor, 24/7-Betrieb | R3 E2E-Betrieb, Ownership at level | Direct |
| * | **BS-6** | **Linux-Serverlandschaft administriert und automatisiert** (ML-Plattform, Docker-Hosts, Backend, Ansible-Control); **Ansible-Erweiterungen entwickelt** — u.a. Credential-Plugin mit lokalem Caching gegen Keystore-Abrufe | **Q2 + R3 + R4 — the bullet that turns the operating layer from Gap to evidence.** Ansible-Erweiterung ist Infrastruktur-Engineering, nicht Toolnutzung | **Direct** |
| x | BS-5 | Spotfire + TAF 2022 | BI, wrong axis here | — |
### Fraunhofer CML — (Feb 2017 Jan 2020)
| | ID | Achievement | JD hook | Match |
|---|---|---|---|---|
| * | FC-3 | Containerisierte Microservices (Docker) für die MISSION-Datenaustauschplattform | early Docker/microservice depth | Adjacent |
| o | FC-1 | Jenkins-CI/CD eigenständig eingeführt | Q2 automation initiative | Adjacent |
| x | FC-2 | ARTUS NLP/Spracherkennung | model work, not operations | — |
### Vizrt — (2015 2017)
| | ID | Achievement | JD hook | Match |
|---|---|---|---|---|
| * | VZ-1 | Python/C++ Backend für ein **verteiltes** Video-Transcoding-System | JD: *"grosse, verteilte Dateninfrastruktur"* — the only distributed-systems evidence outside data pipelines. Scope: contributed; broadcasters are product context, never delivery claims | Bridge |
| o | VZ-2 | Automatisierte A/V-Testsuite + Quality Gates in CI/CD | CI/CD depth | Adjacent |
### Projekte (neuer Abschnitt — empfohlen)
| | ID | Achievement | JD hook | Match |
|---|---|---|---|---|
| * | **PP-3** | **Eigener Debian-Server, seit ~10 Jahren selbst betrieben, administriert und gehärtet** — nginx, Mailserver, Nextcloud, VPN, Docker-Dienste, Bitwarden | **R4 Hardening/Security-Konfiguration — the only *current* and *continuous* Linux evidence** (Bosch ended 2022). Belegt zugleich Q3/Q4: echtes Interesse am ganzen Stack, nicht behauptet sondern seit einem Jahrzehnt gelebt | Direct (personal) |
| x | PP-1 | Investing-/Signal-Plattform | wrong domain here | — |
**PP-3 wording discipline:** never enterprise/production/multi-user, no uptime or scale figures, always visibly a personal self-hosted system. Framed that way it is a strength for this employer — a candidate who runs and hardens his own mail and VPN server is exactly the profile a `Dhall`/`Pull-GitOps` team recognises.
### Generali — omit entirely (LOW on every axis for this JD)
**Recommended total: 12** — SW-3, SW-2, SW-1, SW-7, BS-1, **BS-6**, BS-4, BS-2, BS-3, FC-3, VZ-1, plus **PP-3** in a Projekte section. **Inside the 1114 budget**, 2 discretionary slots left. Fill order if wanted: FC-1 (CI/CD-Initiative), SW-8 (aktuelles KI-Signal), VZ-2. SW-5 now unnecessary — BS-6 and PP-3 carry the security/hardening axis far better than a rotating Security-Champion role.
**Not writable, by canonical rule:**
- **The word GitOps** — resolved 2026-08-27 and the answer was no: Git-versioned, but push-executed from Jenkins/GitLab, no reconciliation agent. Write the substance instead: *"versionskontrollierte Infrastrukturautomatisierung mit Ansible aus Git, ausgeführt über Jenkins-/GitLab-Pipelines."* Against a team that names **Pull-GitOps** in its own posting, that precision reads better than the buzzword.
- **Physical datacenter work** — no experience. Interest belongs in the cover letter, never in a bullet.
- GPGPU; ClickHouse by name; Terraform. Hardening: writable, but visibly sourced to PP-3.
**Phase 2 issues to settle before generation:**
1. **German templates do not exist yet.** Every prior package is English, including SBB's German-language JD. Section headings, date formats and the skills block all need German equivalents in the `.tex`.
2. **Position titles in a German document** — keep the official English titles, or render them in German? Bosch's own Zeugnis title is German.
3. Bosch title variant: `experience_bosch.md` sanctions "Data & ML Engineer" for ML-leaning JDs; that fits the MLOps framing here.
## Critique Context
- **Reviewer persona:** a Bund technical lead in a security-cleared ICT unit, reading in German, who will check Linux depth and operating experience first and data-platform breadth second.
- **Domain vocabulary:** Betrieb, IKT-Schicht, Systemlandschaft, Härtung, Verfügbarkeit, Lebenszyklus, Deployment-Zyklus, Datenplattform, Observability.
- **Likely first technical challenge:** *"Beschreibe eine Linux-Systemlandschaft, die du selbst betrieben und gehärtet hast."* He can answer with the professionally administered Bosch estate (BS-6) and must separate it clearly from the current personal Debian hardening evidence (PP-3).
- **Second challenge:** distinguish the Git-versioned, push-executed Ansible flow from Pull-GitOps; then address the physical-datacenter gap directly.
## Cover Letter Plan
- **Decision: YES — but only if the gates clear.** A Swiss federal application in German expects a Motivationsschreiben, and this role needs prose to do two things a resume cannot: explain why a data engineer is applying to an operating-layer role, and address the second-language question openly instead of letting the reader find it.
- **Language: German.** Non-negotiable for this employer.
- **Paragraph structure:** (1) NDP and the data platform, concretely — why this specific platform; (2) the data half he brings — Kafka, governed pipelines with on-call ownership, ML inference in 24/7 production; (3) honest positioning on the operating layer and the language, without a defensive gap list (`cl_reference.md` bans that — the Aker BP CL-A finding); (4) local, long-term, native German, EU/B permit.
- **Verified hooks:** Neue Digitalisierungsplattform and the datacenter consolidation; Kdo Cy's founding in Jan 2024; Zimmerwald/ZEO as the site. All from first-party or press sources dated in the session, none inferred.
- **Jargon level:** German technical, Bund register, no Anglicism padding.
## Status
- **Phase 0: DONE** — 2026-08-27
- **Fit gate: PASS.** Evidence Fit **79/100 (Core, lower end)**, hard gate **PASS**. The original language and citizenship questions are resolved; the physical-datacenter gap remains explicit.
- **Phase 1: DONE 2026-08-27** — plan confirmed by user. The original count was recorded incorrectly; the generated CV had 15 bullets, not 13.
- **Phase 2: DONE after Edit 2, 2026-08-27** — German resume and motivation letter edited, compiled and visually inspected.
- Language **German**, position titles **English** (user decision). First German-language package in the log; headings, dates and the skills block were built for it (`ngerman` babel added).
- **15 bullets:** Swisscom 4 (SW-2, SW-3, SW-1, SW-7) · Bosch 6 (BS-1, **BS-6** ×2, BS-4, BS-2, BS-3) · Fraunhofer 1 (FC-3+FC-1) · Vizrt 1 (VZ-1+VZ-2) · Generali 1 (GN-1) · **Bundeswehr 1 (BW-1)** · **Projekte 1 (PP-3)**.
- **User-directed content change:** the weak SW-8 LLM-configuration bullet was removed and replaced with the role-specific USP, the six-year Bundeswehr officer career. BW-1 is now canonical and appears in the summary and as a separate experience entry.
- **Deviation from the proposed plan, deliberate: Generali was re-included.** The plan said omit, but a DACH-convention CV should not carry an unexplained 20152017 gap. Capgemini stays omitted per the standing user preference.
- **Verification:** canonical and document validators **PASS, 0 warnings**; MiKTeX pdflatex **2-page CV + 1-page letter, 0 overfull/underfull boxes**; `pdftotext` extraction order correct; visual review clean; forbidden/requested-term sweep **0 hits**.
- **Punctuation:** no Unicode en/em dash and no rendered narrative dash punctuation remain in either source. LaTeX double hyphens remain only for date ranges.
- **Critique v3 is CURRENT, 2026-08-27.** Evidence Fit **79/Core**, hard gate **PASS**, Document Quality **92/100**, Channel **Weak**. The Bundeswehr evidence strengthens the competitive and motivation narrative but does not add technical, intelligence or clearance fit points.
- **Known accepted deviation at submission:** the Bosch BS-1 bullet says the automated classification ran *„ohne manuellen Eingriff“*. Canonical BS-1 supports a qualitative reduction in manual classification, not complete elimination. The user reviewed the critique, judged the package good enough and submitted without this proposed fix.
- **Grades omitted** per the `grade_output_rule` of 2026-08-26 (thesis 1.0 stays off the document by default; say the word to include it).
- **Package status: SUBMITTED 2026-08-27.** Await response.
- **Next action:** no document work. Await screening; an optional post-submission call to **Marcel Matthey-Doret, +41 58 46 78409** could clarify Lohnklasse, Engineer-III level and development path and would upgrade the channel only if an actual conversation occurs.
## Submission Record
- **Submitted:** 2026-08-27, user-confirmed.
- **Fit class / score:** Core, Evidence Fit 79/100.
- **Hard gate:** PASS.
- **Document Quality:** 92/100.
- **Channel at submission:** Weak.
- **Outcome:** applied / awaiting response.
- **Documents:** German 2-page CV and German 1-page motivation letter.
- **Known accepted deviation:** the user submitted without applying the critique v3 BS-1 wording correction from *„ohne manuellen Eingriff“* to a qualitative reduction claim.
- **Cohort:** evidence-first-2026-01, application 5/10; Core 3/7, Adjacent 2/2, Stretch 0/1.
## Output Files
- Session: `output/KdoCy_DevOps_Data_Platform/session_kdocy_devops_data_platform.md`
- Verbatim JD: `output/KdoCy_DevOps_Data_Platform/JD_kdocy_devops_data_platform.txt`
- Resume source: `output/KdoCy_DevOps_Data_Platform/e2e_kdocy_devops_data_platform_resume.tex`
- Resume PDF: `Dennis_Thiessen_Lebenslauf.pdf` (2 pages, German)
- Cover letter source: `e2e_kdocy_devops_data_platform_cover_letter.tex`
- Cover letter PDF: `Dennis_Thiessen_Motivationsschreiben.pdf`**CURRENT after Edit 2**, German, 1 page, **300 body words**, validator PASS, 0 boxes. Addressed to Marcel Matthey-Doret by name.
- Critique: **CURRENT v3, 2026-08-27**, `critique_kdocy_devops_data_platform.md`. Evidence Fit **79/Core**, Document Quality **92/100**, Channel **Weak**, hard gate **PASS**. The remaining BS-1 wording finding was knowingly accepted by the user at submission.
## Cover Letter — decisions taken at write time (2026-08-27)
- **Hooks are 100% first-party from the verbatim posting** (the JD's own MLOps/GPGPU + Linux-layer combination, the reference number, the named contact). No external claim needed verification because none was used.
- **The NDP hook was dropped.** Kdo Cy's Neue Digitalisierungsplattform is verified as a real programme, but nothing establishes that *this* data platform is part of it. Asserting the link would have been an inference dressed as familiarity. `cl_reference.md`: omit a hook rather than spend a paragraph proving company familiarity.
- **The second-Amtssprache question is deliberately NOT raised — a reversal of the Phase 0 plan.** That plan was written while the requirement still looked like a gate. The user then confirmed it is not a hard requirement, so naming it in the letter would hand the reader an objection they had already set aside. This is exactly the Aker BP **CL-A** finding ("I have not authored an enterprise governance framework myself"). The letter states the language assets positively instead; the topic belongs in the interview if it comes up.
- **The physical-datacenter point is framed as motivation, never as evidence** — *"Dass die Stelle über den gesamten Stack geht, bis in den Serverraum, ist für mich ein Argument dafür"*, carried by PP-3, which is visibly personal.
- **Overqualification is answered implicitly, not raised explicitly** — the closing asks about the platform's role in the team's Zielbild, which invites the level conversation without conceding anything.
- Bundle §S5 of `bundle_ml_ai_engineer.md` was checked for the scope-violation pattern found in `bundle_data_engineer.md` on 2026-08-21. **Clean** — its hook matches BS-1's canonical scope.
## Critique v3 (2026-08-27, after Edit 2)
- **Evidence Fit:** 79/100, Core (lower end). **Hard gate:** PASS. The new BW-1 evidence materially improves military-context credibility and motivation but does not establish technical military work, intelligence experience or clearance, so the fit score remains unchanged.
- **Document Quality:** 92/100. **Channel:** Weak.
- **Tier 1:** BS-1 currently says the automated defect classification ran *„ohne manuellen Eingriff“*. Canonical BS-1 supports qualitative reduction of manual classification, not complete elimination. Safe direction: *„... ermöglichte damit die automatisierte bildbasierte Defektklassifikation und reduzierte den manuellen Klassifikationsaufwand.“*
- **Tier 2:** compress the five-line summary; change *„CloudFormation als Infrastructure as Code, IaC“* to *„CloudFormation für Infrastructure as Code (IaC)“*; specify *„mir vertrautes militärisches Umfeld“* in the letter.
- **Mechanical re-check:** validators PASS with 0 warnings; CV 2 pages, letter 1 page; 0 box warnings; A4; extraction order correct; all three pages visually clean; footer 2/2 inside page bounds; no Unicode dash punctuation in either source.
## Edit History
### Edit 1 (2026-08-27): three Tier 1 relevance fixes
- **Source:** `critique_kdocy_devops_data_platform.md`, Tier 1 items 13. User approved with "apply tier 1 fixes".
- **Changes, all MODIFY — no bullet added, removed or swapped, no claim, scope or hedged verb touched:**
1. SW-3: "von der containerisierten Auslieferung" → **"vom Container-Build über das Deployment"**. The JD's own phrase is *"den gesamten Deployment-Zyklus verantworten"*. Deliberately descriptive — *verantworte* was **not** used, because SW-3's canonical scope is "within the team environment" and an ownership verb here would have been an escalation.
2. BS-4: "für Monitoring und Alarmierung" → **"für Monitoring, Logging und Alarmierung"**. Logstash and Loki are the logging half; the bullet had been under-describing work already done.
3. Skills: "Container und Cloud" → **"Container, Cloud und MLOps"**, with "Deployment und Betrieb containerisierter ML-Inferenz (MLOps)". Labelled as the demonstrated work (BS-1 + BS-6), never as a generic MLOps toolchain.
- **Result:** JD-term coverage **64% → 69%** (27/39). *Deployment* and *Logging* now present; *MLOps* now in the CV, not only the letter.
- **Verification:** validator **PASS, 0 warnings** · **2 pages** · **0 overfull/underfull boxes** · forbidden-term sweep over the rendered PDF **0 hits** · visual check clean, no new orphan or header wrap.
- **Delta vs baseline:** pages 2→2, boxes 0→0, char violations 0→0, bullets 13→13, coverage 64%→69%.
- **Estimated post-edit Document Quality ~92/100** (Relevance 11→14.5 of 15). **This is an estimate, not a scored critique — never quote it as a score.** Re-run `/critique` if a current number is needed.
- **Not applied:** Tier 2 items 47 and Tier 3 items 810 remain open, including the Performance/Skalierbarkeit rationale on the Ansible-plugin bullet (Tier 2 #5) and the near-verbatim CV sentence in the cover letter (Tier 2 #7).
### Edit 2 (2026-08-27): German language pass, Tier 2 fixes and Bundeswehr USP
- **Source:** direct user feedback in this session.
- **User-requested language edits:** removed C++/JavaScript and the word *begrenzt* from Skills; changed *Baue und betreibe* to *Entwickle und betreibe*; rewrote the Vizrt bullet in technical language; removed awkward constructions throughout the CV and letter.
- **Dash punctuation:** removed all Unicode en/em dashes and all narrative LaTeX dash punctuation from both `.tex` files. LaTeX double hyphens remain only where they correctly render date ranges.
- **Tier 2:** spelled out *Infrastructure as Code* beside IaC; added the canonically supported Performance/Skalierbarkeit outcome to BS-6; named Swisscom in the summary; fully paraphrased the Bosch cover-letter evidence around the operating constraint.
- **Content selection:** added canonical employment record `BUNDESWEHR` and claim **BW-1** from the existing structured extraction and experience file. Replaced SW-8 with a dedicated Bundeswehr entry; surfaced the six-year officer career in the summary and in the letter's motivation. No clearance, NATO, combat, command-scope or technical military claim was added.
- **Cover letter:** now 300 body words and uses the officer career as the personal motivation for returning to a military environment and contributing to the protection of Switzerland and its population.
- **Verification:** canonical system PASS, 0 warnings; both document validators PASS; CV 2 pages, letter 1 page; 0 overfull/underfull boxes; `pdftotext` order correct; visual inspection clean; 15 bullets before and after content swap.
- **Critique status:** v2 is stale after this material edit. Evidence Fit remains 79/Core; Document Quality was not re-scored.
@@ -0,0 +1,70 @@
Source URL: https://jobs.ruag.ch/offene-stellen/ai-engineer-c5i/4afaa9aa-74c1-4b4d-9232-cf65651ce8ec
Apply URL: https://jobs.ruag.ch/umantis/2514/de/apply/18027
Retrieved: 2026-08-27
Status at retrieval: LIVE; application form reachable
Official portal listing: Berufserfahrene, Thun, Schweiz, 80-100%
AI Engineer C5I (w/m/d)
Rund 3000 Mitarbeitende von RUAG und RUAG Real Estate leisten jeden Tag einen wesentlichen Beitrag zur Sicherheit der Schweiz. Sie sorgen dafür, dass die Schweizer Armee sowie andere Einsatz- und Sicherheitsorganisationen ihre Aufgaben jederzeit umfassend wahrnehmen können.
Das kannst du bewegen
* Aufbau, Weiterentwicklung und Betrieb einer internen AI-/LLM-Plattform inkl. Compute Cluster
* Implementierung von Inhouse LLM-Lösungen inkl. Connectors, Tools und Retrieval-/Dokumentenlösungen
* Entwicklung von Datenpipelines, Data Preprocessing und Schnittstellen zu internen Systemen
* Umsetzung von Proof of Concepts (POCs), MVPs und Pilotlösungen im Bereich AI / R&D
* Containerisierung, Deployment und Automatisierung von AI-Workloads
* Technische Dokumentation sowie Wissenstransfer innerhalb des Teams
Das bringst du mit
* Hochschulabschluss (BSc/MSc) in Informatik, Computer Science, Data Science oder vergleichbar
* Mehrjährige Berufserfahrung in ML- Engineering, Data Engineering, Software Engineering oder DevOps
* Sehr gute Python-Kenntnisse sowie Erfahrung mit modernen ML-/AI- Frameworks
* Erfahrung mit Linux, Docker, Kubernetes oder vergleichbaren Plattformen
* Kenntnisse in LLMs, RAG, APIs, Data Pipelines oder Search-Technologien von Vorteil
* Strukturierte, selbständige und pragmatische Arbeitsweise mit hoher Umsetzungskompetenz
* Sehr gute Deutschkenntnisse in Wort und Schrift; Englischkenntnisse von Vorteil
* Militärische Karriere als höherer Unteroffizier oder Offizier von Vorteil
Erfüllst du nicht alle Voraussetzungen hundertprozentig? Bewirb dich trotzdem. Wir sind stets auf der Suche nach talentierten und motivierten Personen, die unser Team bereichern möchten. Wir legen grossen Wert auf Vielfalt und Chancengleichheit und unser Ziel ist es, ein vielfältiges Team aufzubauen, in dem alle ihre persönlichen Stärken voll entfalten können.
Wir ermutigen insbesondere alle Personen, unabhängig von ihrem Geschlecht, die möglicherweise Bedenken haben, eine Stelle in einem armeenahen Umfeld anzunehmen, sich zu bewerben.
Deine Ansprechperson
Frank Haugwitz
recruiting-c5i@ruag.ch
Arbeitsort
C5I, Uttigenstrasse 36, 3600 Thun
Über den Bereich
Die Business Area C5I der RUAG MRO Holding AG unterstützt die Schweizer Armee bei der Realisierung von IKT-Projekten mit spezifischem Fokus auf das Kommando Cyber. Dies ist deine Chance, einen Beitrag zu hochsicheren und souveränen IT-Systemen zu leisten. Wir sind in den letzten acht Jahren von einem kleinen «Start-up» mit null Mitarbeitenden auf über 260 Mitarbeitende gewachsen und bieten ein einmaliges, dynamisches Umfeld.
Hier kannst du an vorderster Front bei der Digitalisierung der Schweizer Armee mitarbeiten. Willst du einen Beitrag zum sicherheitspolitischen Umfeld leisten? Dann bist du bei uns genau richtig. Wir arbeiten agil und richten uns konsequent nach dem DevSecOps-Modell aus. Mit dem C5I-Campus haben wir einen Innovationsraum für hochsichere IT-Systeme geschaffen und bieten attraktivste Arbeitsplätze. Für fachliche Auskunft steht dir Marco Heinzen, Principal GIS Engineering C5I, gerne zur Verfügung: Tel. +41 79 568 14 96 | Mail marco.heinzen@ruag.ch
Deine Vorteile
Lohn und Nebenleistungen
Wir bieten dir ein leistungsorientiertes- und marktgerechtes Salär, 13 Monatslöhne sowie grosszügige Prämien- und Zulagen. Zusammen mit weiteren Nebenleistungen ergibt sich daraus ein attraktives Gesamtpaket.
Flexibles Arbeiten
Wir legen grossen Wert darauf, dass unsere Mitarbeitenden ein gesundes Gleichgewicht zwischen Beruf und Privatleben finden. Darum bieten wir unter anderem flexible Arbeitszeiten und Homeoffice-Optionen an.
Aufstiegs- und Weiterbildungsmöglichkeiten
Das Potenzial unserer Mitarbeitenden zu fördern und zu entfalten ist uns wichtig. Durch Schulungen, Kurse und Weiterbildungen unterstützen wir sie dabei, ihre Fähigkeiten kontinuierlich auszubauen um ihre beruflichen Ziele zu erreichen.
Wichtige Hinweise zum Bewerbungsprozess
* Vor Anstellungsbeginn wirst du darum gebeten, einen Straf- und Betreibungsregisterauszug vorzuweisen.
* Bewerbungen nehmen wir ausschliesslich über unser Stellenportal jobs.ruag.ch entgegen. E-Mail- wie auch Briefbewerbungen können wir leider nicht akzeptieren.
Zusätzliche offizielle RUAG-Karriereinformation, nicht Teil des obigen Stelleninserats:
RUAG führt bei allen neu eintretenden Mitarbeitenden eine Personensicherheitsprüfung durch.
@@ -0,0 +1,200 @@
# Critique: RUAG C5I — AI Engineer C5I (w/m/d) — Round 2
**Date:** 2026-08-27 (Round 2, after Edit 1)
**Round 1:** same day, pre-edit. Evidence Fit 74 · Document Quality **85** · Channel Weak · 3 Tier 1 fixes.
**Documents:** `e2e_ruag_ai_engineer_c5i_resume.tex` (2 pp, **13 bullets**), `e2e_ruag_ai_engineer_c5i_cover_letter.tex` (1 p, **295 body words**, 5 short paragraphs + close)
**JD:** `JD_ruag_ai_engineer_c5i.txt` — verbatim live posting, retrieved 2026-08-27. **JD integrity: PASS.**
> Scored per `critique_framework.md`, which governs over `SKILL.md` §9.3/§9.4: separate Evidence Fit and Document Quality, verdicts rather than invented probabilities, no single overall score. Documents were re-read from disk, not scored from the Round 1 record.
---
## 1. Round 1 findings — resolution status
| # | Finding | Status |
|---|---|---|
| **T1-1** | Cover letter never connected to DevSecOps, C5I or the Army | **CLOSED.** New standalone paragraph carries `SW-5` and names the DevSecOps model and C5I |
| **T1-2** | `PP-3` missing — the only *current* Linux/ops evidence | **CLOSED.** New `Projekte` section; audited clean against PP-3's full forbidden list |
| **T1-3** | `governte Datenprodukte` is not a German word | **CLOSED.** Now `governance-konforme Datenprodukte` |
| **T2-2** | Headline dropped "AI" from a req titled AI Engineer | **CLOSED.** Now his canonical title, `Staff Data, Analytics & AI Engineer` |
| **T2-3** | Four honestly closeable JD terms absent | **CLOSED.** `Wissenstransfer`, `Datenaufbereitung`, `AI-/ML-Workloads`, `Containerisierung` |
| **T2-4** | IBM AI Engineering had no primary-source record | **CLOSED.** Certificate read directly: IBM via Coursera, 4 Jun 2020, verify `3ZBZFVAL6A34`. Recorded as entry #8 in `thiessen_certifications.md` |
| **T2-5** | CL paragraph 2 re-told resume bullets | **CLOSED.** Compressed; the working-style sentence survives |
| **T2-6** | Post-gap pivot conceded without evidence | **CLOSED.** Now anchored: *"wie zuvor bei der ML-Inferenz in Dresden"* |
| **T2-7** | Citizenship volunteered in the letter | **CLOSED by user decision** — cut. Resume header still carries it |
| **T3** | Bullets 910 both opened `Implementierte` | **CLOSED.** Bullet 9 now opens `Baute`; 0 consecutive identical openers |
| **T2-1(a)** | Vizrt title vs canonical `official_title` | **OPEN by user decision**, logged. Unchanged |
**Plus one defect Round 1 did not catch, found during the edit and fixed:** the resume **never loaded `babel`**, so a German document was hyphenated with English patterns (`Hal-bleiterfertigung`, `Tran-skription`, `automa-tisierte`). This was present at baseline and had survived a full visual QA, because nothing *looks* broken — the lines justify and the page is clean. Fixed with `\usepackage[ngerman]{babel}` plus a `\hyphenation{Trans-krip-ti-on}` exception, which also cleared an overfull box the longer headline had introduced.
---
## 2. Fit Verdict and Hard Gates — unchanged, and unchangeable by editing
| Gate | Result |
|---|---|
| Title-defining capability Direct? | **FAIL.** R1 (build/operate an internal AI-/LLM platform incl. compute cluster) and R2 (in-house LLM solutions, connectors, retrieval/document solutions) remain **Adjacent** |
| Minimum qualification a Gap? | **PASS.** None of the eight `Das bringst du mit` items is a Gap |
| Level requires absent scope? | **PASS** |
| Location / authorization | **PASS.** Thun role, Thun resident, German native, EU citizen with Swiss B permit |
| Clearance (PSP) | **UNRESOLVED** |
| Compensation / level | **UNRESOLVED** |
No document change touches any of this. The user overrode this gate on 2026-08-27 with all of it in view; recorded, not re-litigated.
---
## 3. Evidence Fit — 74/100 (unchanged)
| Dimension | Weight | Score | Reasoning |
|---|---:|---:|---|
| Required qualifications | 35 | 29 | Degree, years, Python, Linux/Docker/Kubernetes, German/English Direct. ML/AI-framework half of Q3 Adjacent |
| Core responsibilities | 25 | 17 | R3/R5/R6 Direct, R4 Direct-to-Adjacent; R1 and R2 Adjacent |
| Level and ownership | 15 | 11 | Staff plus Component/Application Owner exceeds "Berufserfahrene"; may be lateral or down-level |
| Recency and depth | 10 | 8 | Python/Kubernetes/data current; production-ML integration ended 2022; LLM evidence configuration-level |
| Domain/tool transfer | 10 | 6 | Compute cluster, GPU, RAG and search are not substitutable by wording |
| Practical constraints | 5 | 3 | Location/language/authorization excellent; PSP and compensation unresolved |
| **Total** | **100** | **74** | Numerically top-of-Adjacent; strategically **Stretch** |
**`PP-3` does not move this score.** It strengthens the *document's* evidence for the operating half of the role, but it is a personal project and cannot convert an Adjacent title-capability into a Direct one. Treating it as fit-moving would be exactly the "bridge valued as highly as direct evidence" error §5 warns against.
---
## 4. Document Quality — 93/100 (was 85)
| Dimension | Weight | R1 | R2 | Reasoning for the change |
|---|---:|---:|---:|---|
| Truth and provenance | 25 | 23 | **24** | IBM AI Engineering now has a primary source, closing the one line a canonical preflight could not confirm. New `PP-3` and `SW-5` content audited clean against their full forbidden lists. The headline is now *more* accurate than before — his real title, not a positioning label he never held. Remaining deduction: the Vizrt title, user-authorized and logged, is still the one line that will not match a Zeugnis |
| Information hierarchy | 20 | 17 | **19** | Headline now carries the req's own word above the fold. `Projekte` is cleanly placed and parses correctly. Remaining: the officer career, an explicit JD advantage, still sits on page 2 |
| Bullet evidence and impact | 20 | 16 | **16** | **Unchanged and still the weakest dimension.** 12 of 13 bullets are activity descriptions with no outcome clause; only `BS-1` carries a result. This is the honest consequence of `metrics: unverified` across the KB, not a writing failure — but it is real, and it is what a hiring manager notices |
| Relevance and terminology | 15 | 12 | **15** | Both Round 1 deductions closed. **22/22 claimable JD terms now present**, and all six gap terms (RAG, Retrieval, Compute Cluster, AI-/LLM-Plattform, Connectors, Dokumentenlösungen) remain correctly absent. `MVP/Pilotlösung` and `R&D` stay uncovered because the evidence supports "Proof of Concept" and nothing more — declining to stretch is correct behaviour, not a deduction |
| Skills evidence | 10 | 9 | **9** | All tokens still traced. `Datenaufbereitung` and `AI-/ML-Workloads` are claim-backed. TensorFlow/Keras now rests on a verified certificate. Unchanged deduction: `MLOps` in the headline is an umbrella term with no canonical `skills[]` entry, claim-backed only via BS-1 |
| Mechanics/readability | 10 | 8 | **10** | `governte` fixed. German hyphenation fixed. Cadence: list-terminated bullets **50% → 31%**, consecutive identical openers **1 → 0**. 0 boxes, 0 warnings, correct parse, consistent Swiss orthography |
| **Total** | **100** | **85** | **93** | |
**Truth and provenance 24/25 (9.6/10)** — well clear of the 8/10 automatic-failure floor.
The 8-point rise is almost entirely the closure of named Round 1 deductions plus a defect Round 1 missed. The one dimension that did **not** move is bullet impact, and it is the one that would most change a hiring manager's read — see Tier 2.
---
## 5. Channel Strength — **Weak** (unchanged)
Cold portal application; `jobs.ruag.ch` refuses email and post. **Marco Heinzen's direct mobile (+41 79 568 14 96) is published in the posting and still unused.** Nothing in Edit 1 changed this, and no further document work can. This remains the single highest-value action on the application: one call upgrades the channel to Moderate *and* answers whether C5I is hiring someone who has built an AI platform or someone who can operate one and grow into building it — the question the whole application turns on.
---
## 6. Reader Sequence — Verdicts
**Parser / ATS (Umantis). PASS.** `pdftotext -layout` extracts employer, title, dates, location and section order correctly on both pages; the new `Projekte` block parses cleanly; footers read 1/2 and 2/2. No tables, text boxes or multi-column body.
**Recruiter glance (10 s) — Frank Haugwitz. FORWARD.** *The Round 1 friction point is gone.* He is filling a req titled **AI Engineer**, and the headline now reads `Staff Data, Analytics & AI Engineer` — the candidate's real title, containing the word, above the fold, alongside Thun, citizenship, permit and native German. Every box he owns is answered before he scrolls.
**HR / dossier completeness (30 s). COMPLETE.** Two pages, no photo, clean chronology, education, languages, work authorization, `Militärischer Werdegang`, and now a `Projekte` section — which reads as a fuller local dossier, appropriate for a traditional Swiss employer. The Nov 2014 Mai 2015 gap remains intentional and unremarkable.
**Hiring manager (2 min) — Marco Heinzen. Still MAYBE, but a stronger MAYBE.** The underlying split is unchanged: if his brief is "build our RAG stack", this is a no; if it is "run the platform and the pipelines while we grow the AI layer", it is a strong yes. What changed is that the letter now argues the second case more completely — it names his DevSecOps practice against C5I's stated operating model, and the pivot after the gap admission is anchored in something he has actually done rather than in an intention. The resume now also shows *current* hands-on infrastructure, not only work that stopped in 2022.
**Technical reviewer (10 min). CREDIBLE.** No claim collapses. Likely probes, in order: (1) "You configured the assistants — who built the platform underneath?" (2) "Compute cluster — what is the largest thing you have operated, and have you scheduled GPU workloads?" (3) **new:** "Your private server — what have you actually hardened, and how do you patch it?" This is a probe the document now *invites*, and it is a good one to invite. (4) The 20082014 / 20092013 officer-track overlap. (5) Ansible vs Pull-GitOps — the word is still correctly absent and the substance is answerable.
---
## 7. Claim Audit — new and changed content only
| Claim | Canonical | Safe? | Note |
|---|---|---|---|
| Headline `Staff Data, Analytics & AI Engineer` | `claims.json` SWISSCOM `title_history` / current title | ✓ | Now his **actual** title. More accurate than the Round 1 headline |
| Profil opener, same title | as above | ✓ | Consistent with headline and body |
| `governance-konforme Datenprodukte innerhalb des unternehmensweiten AWS Data Mesh` | SW-7 | ✓ | Object still scoped; mesh still not claimed |
| **`Projekte`: private Debian server** | **PP-3** | ✓ | Verbs `Betreibt`/`administriert`/`verantwortet Systemhärtung` all in `allowed_verbs`. "selbst gehostet" stated; section reads `Eigenbetrieb`. **No** enterprise/production/multi-user/business-critical wording, **no** uptime/availability/SLA/user-count/scale figure, **no** SRE or sysadmin implication, **no** datacenter claim. Audited against all five forbidden items |
| `koordinierte Hersteller, technische Dokumentation und Wissenstransfer an die Nutzer` | BS-3 | ✓ | All four BS-3 elements retained (SLOs, vendors, documentation, training) in natural German |
| `Baute einen ELK/Kafka-Proof-of-Concept` | BS-4 | ✓ | `built` is an allowed verb; PoC status still explicit |
| Skills `Datenaufbereitung` | SW-1 / SW-2 / BS-2 | ✓ | Real work, previously unnamed |
| Skills `Containerisierung und Deployment von AI-/ML-Workloads` | BS-1 / BS-6 | ✓ | No new claim; renames existing evidence in the JD's vocabulary |
| Cert `IBM AI Engineering mit TensorFlow/Keras im Weiterbildungskontext` | `thiessen_certifications.md` #8 | ✓ | **Now primary-source verified.** Still correctly confined to certification context |
| **CL:** `Für 2025/2026 bin ich Security Champion meines Teams, mit 100 Stunden Training…` | SW-5 | ✓ | Single year only. Team role, not an award. Does **not** claim DevSecOps compliance ownership |
| **CL:** `Dass C5I konsequent nach dem DevSecOps-Modell arbeitet, entspricht damit meiner heutigen Praxis` | SW-5 + SW-3 | ✓ | A soft alignment claim, supported by the Security Champion role, 100 h training and GitLab CI/CD automation. See Tier 2 — expect it to be probed |
| **CL:** `die Implementierungsseite erarbeite ich mir von dort aus, wie zuvor bei der ML-Inferenz in Dresden` | BS-1 | ✓ | Back-reference to real work; introduces no new claim |
| Citizenship sentence removed from CL | — | ✓ | Resume header still carries `Deutscher Staatsbürger` / `Schweizer Aufenthaltsbewilligung B`, so nothing is concealed |
**No Tier 1 truth finding.** Full sweep across both `.tex` sources and both extracted PDFs: **0 hits** for Capgemini, LangChain/LangGraph/LlamaIndex, Terraform, Azure, GCP, GitOps, TypeScript, FastAPI, Flask, Django, every `global_forbidden_output_patterns` entry, and the standalone acronym `RAG` (word-boundary count 0 — the only `rag` matches are inside *Fragen* and *Abfragen*). **0 em dashes.**
---
## 8. Tiered Improvements
### Tier 1 — none.
No truth, fit or relevance defect remains that is fixable by editing. This is the honest result of Round 1's fixes, not a courtesy.
### Tier 2
**T2-A · Bullet impact is now the document's weakest dimension, and it is a KB problem, not a writing problem.**
12 of 13 bullets describe activity with no outcome. `BS-1` is the only bullet that says what changed. Every other claim in `claims.json` carries `metrics: unverified`, and inventing figures is barred — so the resume is correctly written but structurally flat where a hiring manager looks for consequence. **The fix is upstream:** if any verified outcome exists for `SW-2` (incident or SLA record), `SW-3` (deployment frequency, service count), `SW-7` (data products delivered, sources onboarded) or `BS-3` (applications owned), recording it in `claims.json` would raise this dimension across every future package, not just this one. Do not invent anything to close it here.
**T2-B · The officer career still sits on page 2.**
The JD names it explicitly as an advantage, and it is the one thing most competing software candidates cannot offer. It is mitigated by the profile sentence, and moving the section would break reverse chronology. Structural; accepted rather than fixed.
**T2-C · The headline now duplicates the Swisscom title line verbatim.**
Both read `Staff Data, Analytics & AI Engineer`. Accurate and defensible — it is his title — but the repetition is visible within the first fifteen lines. Optional: differentiate the headline's tail (it currently carries `Python · Kubernetes · MLOps`) or leave it. Cosmetic only.
**T2-D · Prepare the DevSecOps sentence for a follow-up question.**
*"…entspricht damit meiner heutigen Praxis"* is a soft alignment claim. It is supported — Security Champion, 100 h training, GitLab CI/CD — but a security-conscious reader may ask what DevSecOps actually looks like in his current team, and the honest answer is that he is the team's security point of contact, not the owner of a DevSecOps pipeline. Worth having ready; not worth rewording.
### Tier 3
- **Bosch bullet lengths cluster** at 19/22/17/18 words — a 5-word spread, just above §7a's flagged threshold of ≤4. The validator passes it. Diagnostic only; do not pad or trim to move it.
- **`\today`** renders "27. August 2026". If the built PDF is submitted later, recompile so the date refreshes.
- **`MLOps`** in the headline remains an umbrella term with no canonical `skills[]` entry. Claim-backed via BS-1; keep.
---
## 9. Cover Letter Critique
**6A — Anti-patterns. PASS.** No generic opener, no company-history paraphrase, no adjective stack, no defensive gap list. Opens on the candidate-role connection in the first clause. 0 em dashes. The gap sentence — *"Eine AI-Plattform habe ich nicht aufgebaut"* — remains one sentence, immediately followed by what he does bring, and is now followed by evidence rather than intention.
**6B — Tailoring. PASS (was Partial).** The Round 1 deduction is closed. The letter now engages the posting's own `Über den Bereich` framing by name — **C5I** and the **DevSecOps model** — and does so through evidence that was already on the resume rather than through company-research filler. The role thesis in paragraph 1 still derives directly from the JD's first two bullets.
**6C — Context-specific. PASS.** Defence motivation correctly bounded: *"im Umfeld von Landesverteidigung und gesellschaftlicher Verantwortung"*, never rejoining the armed forces. *"ich wohne in Thun, also am Standort selbst"* remains the strongest practical line in the package.
**6D — ATS.** Not a factor; the letter supplements the CV in a portal upload.
**6E — Structural. PASS.** 295 body words (target 250300). Six blocks with good variation — 50 / 52 / 77 / 35 / 63 / 18 words — and no paragraph dominating the page after the split. One page, 0 boxes. Swiss orthography consistent (*Grüsse*, *einschliesslich*). Salutation correctly without a comma. Addressed to the named Ansprechperson at the verbatim-verified legal entity and address. `cl_reference.md`'s "two or three short paragraphs" is the International-Tech default; line 49 explicitly permits an employer-appropriate motivation-statement format, and five short German paragraphs serve this reader better than three long ones.
**6F — Package cohesion. PASS.** Every letter claim maps to a resume bullet and a canonical ID (BS-1, BS-6, SW-3, SW-2, SW-8, **SW-5**, BW-1). No new tool, metric, customer or ownership claim. The LLM boundary is stated identically in both documents. Contact block and location consistent. Citizenship now appears in exactly one place — the resume header — which is the right number.
**Would deleting the letter improve the application? No.** It is now doing more work than in Round 1: it answers the question the resume structurally cannot — what this candidate thinks he is applying for, given what he has not done — and it connects his current security practice to the employer's stated operating model.
---
## 10. Mechanical Verification — re-run on the edited files
| Check | Resume | Cover letter |
|---|---|---|
| `validate_resume_system.py --document` | **PASS, 0 warnings** | **PASS, 0 warnings** |
| Canonical system validator | **PASS, 0 warnings** | — |
| `claims.json` parses after the PyTorch patch | **valid JSON** | — |
| MiKTeX, two passes | **PASS** | **PASS** |
| Page count | **2** (exact) | **1** (exact) |
| Overfull / Underfull boxes | **0** | **0** |
| LaTeX warnings | **0** | **0** |
| `pdftotext -layout` order | employer / title / date / location / sections correct incl. new `Projekte`; footers 1/2, 2/2 | correct |
| German hyphenation | **ngerman**`Halb-leiterfertigung`, `Trans-krip-tion`, `automati-sierte` | ngerman (was already loaded) |
| Visual QA at 130 dpi | both pages re-rendered and inspected after every edit | re-rendered and inspected after the split |
| Submission copy refreshed + MD5 match | **yes** | **yes** |
| PDF newer than `.tex` | **yes** — no unbuilt edits pending | **yes** |
**Content checks.** Email `dennis@thiessen.io` ✓. `Thun, Schweiz` on both; Swisscom entry keeps `Bern, Schweiz` ✓. Capgemini 0 ✓. All forbidden skills 0 ✓. All global-forbidden patterns 0 ✓. French/Italian absent ✓. No DOB, marital status, gender, children or photo ✓. No LOC or test counts ✓. Certifications appear exactly once ✓.
**Structural.** 13 bullets (1114 guide ✓). Six skills lines (46 guide, sixth is Zertifizierungen ✓). Profile 4 rendered lines, one over the 23 guide but carrying three distinct positioning claims; not flagged. Reverse chronology intact. `Militärischer Werdegang` and `Projekte` correctly separated from `Berufserfahrung`.
---
## 11. Summary
**Evidence Fit 74/100 · Stretch · title-capability gate FAIL · PSP and compensation UNRESOLVED — all unchanged.**
**Document Quality 93/100 (was 85) · truth and provenance 24/25 · no Tier 1 findings of any kind.**
**Channel Weak — unchanged, and the published direct line is still unused.**
The documents are now as good as this evidence base allows. Every Round 1 finding is closed except the Vizrt title, which is a conscious user decision, and bullet impact, which is a `claims.json` limitation rather than a writing one.
Per `critique_framework.md`, a high Document Quality score does not make this package submit-ready, and 93 does not mean 93% likely to interview. The gate still reads FAIL. What decides this application is not the documents — it is whether C5I wants the platform's AI layer or its operating layer, and that is answered by a phone call, not by another edit.
@@ -0,0 +1,69 @@
% RUAG C5I: AI Engineer C5I (w/m/d). German-language Swiss/DACH letter.
% Every claim traces to a resume bullet and a canonical ID.
% Boundaries enforced here:
% - SW-8 stays configuration-level. No RAG, retrieval, orchestration, evaluation or fine-tuning.
% - No AI/LLM-platform ownership and no compute/GPU-cluster operation is implied anywhere.
% - BS-1 does not claim model training.
% - BW-1: no clearance, no command scope, no technical military work.
% - RUAG is a defence contractor, not the armed forces. The letter says "im Umfeld von
% Landesverteidigung", never "wieder Teil der Armee".
% - The LLM gap is named once, briefly and without apology. The JD invites applicants who do
% not meet every requirement, so an honest bridge reads as candour, not as a defensive list.
% - SW-5 (Security Champion 2025/2026, 100 h training) answers the JD's stated DevSecOps model.
% Team role only, never an award, never DevSecOps compliance ownership.
% - Citizenship is deliberately NOT restated here (user decision 2026-08-27); the resume header
% already carries "Deutscher Staatsbuerger" and "Schweizer Aufenthaltsbewilligung B".
% Contact location is Thun, matching the resume and the Thun-area rule in config.md.
\documentclass[11pt,a4paper]{article}
\usepackage[utf8]{inputenc}
\usepackage[T1]{fontenc}
\usepackage[ngerman]{babel}
\usepackage{lmodern}
\usepackage[a4paper,left=0.85in,right=0.85in,top=0.7in,bottom=0.7in]{geometry}
\usepackage{parskip}
\usepackage{xcolor}
\usepackage{hyperref}
\hypersetup{hidelinks}
\pagestyle{empty}
\setlength{\parindent}{0pt}
\begin{document}
{\Large\bfseries Dennis Thiessen, M.Eng.}\par
Thun, Schweiz $\vert$
\href{mailto:dennis@thiessen.io}{dennis@thiessen.io} $\vert$ +41 795 955 585 $\vert$
\href{https://linkedin.com/in/dennis-thiessen}{LinkedIn}
\vspace{1.5em}
RUAG MRO Holding AG, Business Area C5I\\
Herr Frank Haugwitz\\
Uttigenstrasse 36, 3600 Thun
\vspace{1em}
\today
\vspace{1em}
\textbf{Bewerbung als AI Engineer C5I (w/m/d)}
\vspace{0.8em}
Sehr geehrter Herr Haugwitz
Ihre Ausschreibung verbindet zwei Aufgaben, die in meiner Arbeit ohnehin zusammengehören: eine interne Plattform für AI-Workloads zu betreiben und die Datenpipelines und Schnittstellen zu bauen, von denen diese Workloads leben. An dieser Schnittstelle arbeite ich seit Jahren, zuerst in der Halbleiterfertigung bei Bosch, heute bei Swisscom auf Kubernetes und AWS.
Bei Bosch in Dresden integrierte ich ML-Inferenz als Docker-Container mit Kubernetes und Ansible in die kontinuierlich laufende Fertigung; die Klassifikation von Defektbildern lief danach vollautomatisiert. Die Linux-Server darunter administrierte ich selbst und automatisierte ihre Konfiguration mit Ansible, inklusive eigener Erweiterungen. In einer Fertigung ohne Stillstandstoleranz zeigt sich früh, ob eine Automatisierung trägt.
Heute entwickle und betreibe ich bei Swisscom Python-Datenanwendungen auf Kubernetes und verantworte als Component Owner geschäftskritische ETL-Strecken von Oracle und Kafka ins Data Warehouse, einschliesslich Rufbereitschaft. Meine LLM-Erfahrung möchte ich klar einordnen: Ich konfiguriere domänengestützte Assistenten in einer Swisscom-eigenen Oberfläche und arbeite über LiteLLM mit Modell-APIs. Eine AI-Plattform habe ich nicht aufgebaut. Was ich mitbringe, ist die Betriebs- und Plattformseite dieser Rolle; die Implementierungsseite erarbeite ich mir von dort aus, wie zuvor bei der ML-Inferenz in Dresden.
Sicherheit ist dabei kein Anhang: Für 2025/2026 bin ich Security Champion meines Teams, mit 100 Stunden Training zu Cloud Security, DevSecOps und Security by Design. Dass C5I konsequent nach dem DevSecOps-Modell arbeitet, entspricht damit meiner heutigen Praxis.
Die Aufgabe hat für mich auch persönlich Gewicht. Ich diente sechs Jahre in der Bundeswehr, absolvierte den Offizieranwärterlehrgang und die Offizierschule und schied als Leutnant aus. Nach über zehn Jahren in der Industrie wieder im Umfeld von Landesverteidigung und gesellschaftlicher Verantwortung zu arbeiten, ist ein wesentlicher Grund für diese Bewerbung. Deutsch ist meine Muttersprache, und ich wohne in Thun, also am Standort selbst.
Über ein Gespräch würde ich mich freuen, besonders darüber, wie Plattform und erste Inhouse-Lösungen bei Ihnen zusammenspielen sollen.
Freundliche Grüsse
\vspace{1.5em}
Dennis Thiessen
\end{document}
@@ -0,0 +1,92 @@
\documentclass{resume}
\usepackage[utf8]{inputenc}
\usepackage[T1]{fontenc}
\usepackage[ngerman]{babel}
\usepackage{lmodern}
\usepackage[a4paper,left=0.65in,right=0.65in,top=0.55in,bottom=0.55in]{geometry}
\usepackage{xcolor}
\usepackage{hyperref}
\hypersetup{hidelinks}
\usepackage[version=4]{mhchem}
\usepackage{fancyhdr}
\pagestyle{fancy}
\fancyhf{}
\renewcommand{\headrulewidth}{0pt}
\fancyfoot[R]{\small \thepage/\pageref{LastPage}}
\hyphenation{Trans-krip-ti-on}
\name{Dennis Thiessen, M.Eng.}
\headline{Staff Data, Analytics \& AI Engineer $\vert$ Python · Kubernetes · MLOps}
\contactline{Thun, Schweiz $\vert$ \href{mailto:dennis@thiessen.io}{dennis@thiessen.io} $\vert$ +41 795 955 585 $\vert$ \href{https://linkedin.com/in/dennis-thiessen}{LinkedIn}\\Deutscher Staatsbürger $\vert$ Schweizer Aufenthaltsbewilligung B\\Deutsch (Muttersprache) $\vert$ Englisch (fliessend)}
\begin{document}
\begin{rSection}{Profil}
Staff Data, Analytics \& AI Engineer mit über zehn Jahren Erfahrung in produktiven Daten- und Softwaresystemen. Verbindet Python/Kubernetes und Linux-/Ansible-Automatisierung mit produktiver ML-Inferenz und der Konfiguration domänengestützter LLM-Assistenten; sechs Jahre Bundeswehr mit abgeschlossener Offizierausbildung ergänzen das Profil.
\end{rSection}
\begin{rSection}{Kenntnisse}
\skillline{Programmierung \& Schnittstellen}{Python, SQL, REST APIs; LiteLLM in aktueller API-Nutzung}
\skillline{AI/ML Engineering}{Containerisierung und Deployment von AI-/ML-Workloads, domänengestützte LLM-Assistenten, NLP/Spracherkennung im Forschungsprojekt}
\skillline{Plattform \& Automation}{Linux, Docker, Kubernetes, Ansible, GitLab CI/CD, Jenkins}
\skillline{Data Engineering}{Kafka, Airflow, PySpark, AWS (S3, Glue, Athena/Iceberg, Redshift), Datenpipelines, Datenaufbereitung}
\skillline{IaC \& Betrieb}{CloudFormation, ELK, Grafana, Prometheus, On-Call-Betrieb, DevSecOps}
\skillline{Zertifizierungen}{AWS Solutions Architect -- Associate, gültig bis Sep. 2027; Data Engineering with AWS, 2026; IBM AI Engineering mit TensorFlow/Keras im Weiterbildungskontext; iSAQB CPSA Foundation}
\end{rSection}
\begin{rSection}{Berufserfahrung}
\begin{rSubsection}{Swisscom (Schweiz) AG}{Okt. 2023 -- heute}{Staff Data, Analytics \& AI Engineer (Engineer IV; Beförderung Apr. 2025)}{Bern, Schweiz}
\item Konfiguriert domänengestützte LLM-Assistenten in einer Swisscom-eigenen Weboberfläche: Auswahl verfügbarer Modelle und kuratierte Wissensgrundlagen für Fragen, Migrationsunterstützung und Datenmapping.
\item Entwickelt, deployt und betreibt Python-Datenanwendungen auf Kubernetes; automatisiert Build, Tests und Deployment mit GitLab CI/CD.
\item Modelliert und implementiert governance-konforme Datenprodukte innerhalb des unternehmensweiten AWS Data Mesh von Swisscom. Onboardet Quellsysteme und dokumentiert Metadaten sowie Lineage in Atlassian Compass.
\item Verantwortet als Component Owner geschäftskritische Fulfillment-ETL-Pipelines von Oracle und Kafka in das Teradata DWH, einschliesslich Data Governance, 2nd/3rd-Level-Support, Rufbereitschaft und SLA-Einhaltung.
\item Übernimmt 2025/2026 die Teamrolle als Security Champion; absolvierte 100 Stunden Training zu Cloud Security, DevSecOps, Security by Design und Risikomanagement mit abschliessender Prüfung.
\end{rSubsection}
\end{rSection}
\newpage
\begin{rSection}{Berufserfahrung (Fortsetzung)}
\begin{rSubsection}{Robert Bosch Semiconductor Manufacturing Dresden GmbH}{Feb. 2020 -- Dez. 2022}{Senior Data Engineer, Data Analysis (Beförderung Jan. 2021)}{Dresden, Deutschland}
\item Integrierte ML-Inferenz als Docker-Container mit Kubernetes und Ansible in die kontinuierliche Halbleiterfertigung. Ermöglichte damit eine vollautomatisierte Klassifikation von Defektbildern.
\item Administrierte Linux-Server für Analyse- und ML-Workloads und automatisierte deren Konfiguration mit Ansible. Entwickelte ein Plugin, das Zugangsdaten lokal zwischenspeicherte und Keystore-Abfragen reduzierte.
\item Verantwortete als Application Owner Analyseanwendungen und vorgelagerte Pipelines; definierte SLOs und koordinierte Hersteller, technische Dokumentation und Wissenstransfer an die Nutzer.
\item Baute einen ELK/Kafka-Proof-of-Concept für Anomalieerkennung und ergänzte das Monitoring um Grafana, Prometheus und Loki.
\end{rSubsection}
\begin{rSubsection}{Fraunhofer-Center für Maritime Logistik und Dienstleistungen CML}{Sep. 2018 -- Okt. 2019}{Wissenschaftlicher Mitarbeiter / Research Software Engineer}{Hamburg, Deutschland}
\item Implementierte im ARTUS-Forschungsteam ML- und NLP-Komponenten für die automatische Transkription von Kommunikation bei Seenotrettungseinsätzen.
\end{rSubsection}
\begin{rSubsection}{Vizrt}{Juli 2017 -- Mai 2018}{DevOps Engineer}{Bergen, Norwegen}
\item Entwickelte Python-Backend-Komponenten für verteiltes Video-Transcoding und integrierte automatisierte Audio-/Video-Tests als Quality Gates in die CI/CD-Pipeline.
\end{rSubsection}
\compactentry{Generali Deutschland Informatik Services GmbH}{Mai 2015 -- Juni 2017}
\textit{IT Consultant}\hfill\textit{Hamburg, Deutschland}\par
\end{rSection}
\begin{rSection}{Militärischer Werdegang}
\begin{rSubsection}{Bundeswehr}{Juli 2008 -- Nov. 2014}{Offizieranwärter / Offizier}{Deutschland}
\item Absolvierte Offizieranwärterlehrgang und Offizierschule während sechsjähriger Dienstzeit; schied im Dienstgrad Leutnant aus der Bundeswehr aus.
\end{rSubsection}
\end{rSection}
\begin{rSection}{Projekte}
\begin{rSubsection}{Privater Debian-Server}{seit rund zehn Jahren}{Eigenbetrieb}{}
\item Betreibt und administriert einen selbst gehosteten Debian-Server mit nginx, Mailserver, Nextcloud, VPN, Docker-Diensten und Bitwarden; verantwortet Systemhärtung und Security-Konfiguration selbst.
\end{rSubsection}
\end{rSection}
\begin{rSection}{Ausbildung}
\compactentry{M.Eng. Computer Aided Engineering}{Apr. 2012 -- Okt. 2013}
Universität der Bundeswehr München, Vertiefung Software Design \& Engineering. Masterarbeit an der Tongji University, Shanghai: \textit{Development of a Web-Based Remote Fault Diagnosis System}; Note 1,0.
\vspace{0.25em}
\compactentry{B.Eng. Information and Telecommunication Technologies}{Okt. 2009 -- Okt. 2012}
Universität der Bundeswehr München.
\end{rSection}
\end{document}
+58
View File
@@ -0,0 +1,58 @@
\ProvidesClass{resume}[2026/07/27 Evidence-first professional resume]
\LoadClass[11pt,a4paper]{article}
\RequirePackage{enumitem}
\RequirePackage{ifthen}
\RequirePackage{lastpage}
\RequirePackage{parskip}
\RequirePackage{needspace}
\pagestyle{empty}
\setlength{\parindent}{0pt}
\def\@resumename{}
\def\@resumeheadline{}
\def\@resumecontact{}
\newcommand{\name}[1]{\def\@resumename{#1}}
\newcommand{\headline}[1]{\def\@resumeheadline{#1}}
\newcommand{\contactline}[1]{\def\@resumecontact{#1}}
\newcommand{\printresumeheader}{%
{\LARGE\bfseries \@resumename}\par
\vspace{0.15em}
\ifthenelse{\equal{\@resumeheadline}{}}{}{\@resumeheadline\par}
\vspace{0.1em}
{\small \@resumecontact}\par
\vspace{0.45em}
}
\AtBeginDocument{\printresumeheader}
\newenvironment{rSection}[1]{%
\vspace{0.35em}
{\bfseries #1}\par
\vspace{0.1em}\hrule\vspace{0.35em}
}{%
\vspace{0.2em}
}
\newenvironment{rSubsection}[4]{%
\Needspace{6\baselineskip}%
{\bfseries #1}\hfill{\small #2}\par
{\itshape #3}\hfill{\itshape #4}\par
\vspace{0.1em}
\begin{itemize}[leftmargin=1.25em,label=\textbullet,itemsep=0.18em,topsep=0.15em,parsep=0pt,partopsep=0pt]
}{%
\end{itemize}
\vspace{0.25em}
}
\newcommand{\skillline}[2]{%
\textbf{#1:} #2\par
\vspace{0.08em}
}
\newcommand{\compactentry}[2]{%
\textbf{#1}\hfill #2\par
}
@@ -0,0 +1,474 @@
# Session: RUAG C5I - AI Engineer C5I (w/m/d)
## JD Integrity
- **File/source:** `JD_ruag_ai_engineer_c5i.txt`; verbatim visible body from `https://jobs.ruag.ch/offene-stellen/ai-engineer-c5i/4afaa9aa-74c1-4b4d-9232-cf65651ce8ec`.
- **Retrieval method and date:** direct web retrieval of the live RUAG posting and apply form, 2026-08-27.
- **Verbatim posting:** YES.
- **Posting status:** LIVE 2026-08-27; application form reachable. Internal application ID 18027, publish ID 10075372.
- **Official portal listing:** Berufserfahrene, Thun, Switzerland, 80-100%.
## Application Decision
- **Audience profile:** Swiss/DACH. German-language posting, Swiss defence employer, local Thun role.
- **Evidence Fit:** **74/100**.
- **Fit class:** **Stretch under `application_strategy.md`**, although the numerical score is at the top of Adjacent. The title-defining AI-/LLM-platform build and in-house LLM implementation are only Adjacent.
- **Hard gate:** **FAIL under the strict `critique_framework.md` title-capability rule.** Dennis has not built or operated an AI-/LLM platform or implemented a production retrieval/document solution. His evidence is real but one layer adjacent: Kubernetes/data-platform operation, professional Linux/Ansible, containerized ML inference integration, LiteLLM/API exposure and configuration of grounded LLM assistants.
- **Channel Strength:** Weak today; upgradeable to Moderate only after an actual conversation.
- **Channel plan:** contact Frank Haugwitz (`recruiting-c5i@ruag.ch`) for compensation/PSP screening and Marco Heinzen (`marco.heinzen@ruag.ch`, +41 79 568 14 96) for technical scope, especially whether the first six months centre on platform engineering or direct RAG/LLM implementation.
- **Cohort slot:** evidence-first-2026-01 currently 5/10: Core 3/7, Adjacent 2/2, Stretch 0/1. Proceeding would consume the sole Stretch slot.
- **Decision:** **PROCEED by explicit user override, 2026-08-27.** The user consciously accepts the title-capability gap, unresolved compensation/PSP questions and use of the cohort's sole Stretch slot. The Evidence Fit, Stretch classification and strict hard-gate result remain unchanged.
## Role and Practical Context
| Field | Current fact |
|---|---|
| Employer | RUAG, Business Area C5I |
| Role | AI Engineer C5I (w/m/d) |
| Location | C5I, Uttigenstrasse 36, 3600 Thun |
| Pensum | 80-100% |
| Target group | Berufserfahrene |
| Technical contact | Marco Heinzen, Principal GIS Engineering C5I, +41 79 568 14 96, `marco.heinzen@ruag.ch` |
| Recruiting contact | Frank Haugwitz, Director Sourcing C5I-Campus, `recruiting-c5i@ruag.ch` |
| Application documents | CV / complete dossier required; motivation letter and certificates optional |
| Work model | Flexible hours and home-office options stated; no cadence promised. Commute is immaterial because the role is in Thun |
| Security process | RUAG states that all new employees undergo a Personensicherheitsprüfung; the JD also requests criminal- and debt-register extracts before employment |
| Compensation | No band. RUAG states market-based pay, 13 monthly salaries and allowances. Small self-reported samples indicate a meaningful risk of a cut versus current approximately CHF 140k; exact role band must be asked |
### PSP / citizenship read
- The posting contains **no Swiss-citizenship requirement**.
- RUAG's official careers page says all new employees undergo a PSP.
- SEPOS states that people resident abroad can in principle undergo a PSP and that third-party/company employees are checked for security-sensitive work. This does not guarantee a positive result or this role's project eligibility.
- German citizenship plus Swiss B work authorization is therefore **not an evidenced automatic disqualifier**, but the role-specific PSP/project-access position remains a practical question for RUAG.
### Compensation read
- Official posting: no salary band; only market-based pay, 13 salaries and benefits.
- Kununu RUAG samples are small and non-authoritative: DevOps Engineer approximately CHF 96.6k (n=2), Data Scientist approximately CHF 106.2k (n=2), Software Developer approximately CHF 110.5k average with CHF 78.3k-138.4k range (n=6).
- These numbers cannot price this vacancy, but they make a material pay cut versus current compensation plausible. The Thun-local exception permits near-current pay, not a large reduction.
## Requirements
| # | Requirement | Req/Pref | Class | Canonical evidence | Gate? |
|---|---|---|---|---|---|
| Q1 | BSc/MSc in Informatics, Computer Science, Data Science or comparable | Required | **Direct** | EDU-MENG (M.Eng. Computer Aided Engineering, Software Design & Engineering); EDU-BENG | - |
| Q2 | Several years in ML Engineering, Data Engineering, Software Engineering or DevOps | Required, disjunctive | **Direct** | SWISSCOM employment + SW-1/SW-2/SW-3; BOSCH + BS-1/BS-2/BS-6; FRAUNHOFER; VIZRT | - |
| Q3 | Very strong Python and experience with modern ML/AI frameworks | Required | **Split: Python Direct, frameworks Adjacent** | Python production-current; FC-2 ML/NLP contribution; BS-1 ML-inference integration; TensorFlow/Keras only certification-context evidence | ⚠ |
| Q4 | Linux, Docker, Kubernetes or comparable platforms | Required, disjunctive | **Direct** | BS-6, PP-3, BS-1, SW-3 | - |
| Q5 | LLM, RAG, APIs, data pipelines or search knowledge | Preferred, disjunctive | **Direct overall / partial** | SW-8 LLM configuration and LiteLLM API exposure; SW-1/SW-2/SW-3 data pipelines. RAG and search implementation remain Gaps | - |
| Q6 | Structured, independent, pragmatic execution | Required behaviour | **Adjacent** | SW-2 Component Owner, BS-3 Application Owner, FC-1 independent CI/CD setup; do not turn these into unsupported personality claims | - |
| Q7 | Very good German; English preferred | Required / preferred | **Direct** | German native, English fluent | - |
| Q8 | Higher NCO or officer career | Preferred | **Direct and differentiating** | BW-1: six years Bundeswehr, officer training/school, left as Second Lieutenant | - |
| C1 | Swiss work authorization | Practical | **Direct** | German citizen, Swiss B permit, no sponsorship required | - |
| C2 | PSP and project access | Practical | **Constraint** | PSP applies to all RUAG entrants; no nationality gate stated; role-specific outcome unknown | ⚠ |
| C3 | Compensation acceptable | Practical | **Constraint** | No published band; external samples suggest downside risk | ⚠ |
## Core Responsibilities
| # | Responsibility | Class | Canonical evidence | Gap boundary |
|---|---|---|---|---|
| R1 | Build, evolve and operate internal AI/LLM platform including compute cluster | **Adjacent, title-defining** | SW-3 Kubernetes/Python operations; BS-6 professional Linux/Ansible; BS-1 ML inference | No AI/LLM platform ownership, compute-cluster or GPU-cluster operation |
| R2 | Implement in-house LLM solutions, connectors, tools, retrieval/document solutions | **Adjacent-to-Gap, title-defining** | SW-8 configured grounded assistants; LiteLLM API hands-on | No production LLM implementation, RAG/retrieval implementation, orchestration or formal evaluation |
| R3 | Develop data pipelines, preprocessing and internal interfaces | **Direct** | SW-1, SW-2, SW-3, SW-6, SW-7, BS-2 | Scope must stay on owned pipelines/data products, not company platform ownership |
| R4 | Deliver AI/R&D PoCs, MVPs and pilots | **Direct-to-Adjacent** | BS-4 anomaly-detection PoC; FC-2 ML/NLP contribution; GN-2 PoCs; academic prototype evidence | No claim of end-to-end ownership of shared research programmes |
| R5 | Containerize, deploy and automate AI workloads | **Direct** | BS-1 Docker/Kubernetes/Ansible ML-inference integration; BS-6 automation | Do not claim model training or full ML lifecycle |
| R6 | Technical documentation and team knowledge transfer | **Direct** | BS-3 documentation/training; GN-1 training and technical ownership | - |
## Evidence Fit Breakdown
| Dimension | Weight | Score | Reasoning |
|---|---:|---:|---|
| Required qualifications | 35 | **29** | Degree, years, Python, Linux/container stack and languages are Direct; modern ML/AI-framework depth is Adjacent |
| Core responsibilities | 25 | **17** | Data pipelines, AI-workload deployment and documentation are Direct; the two leading AI/LLM-platform responsibilities are only Adjacent |
| Level and ownership | 15 | **11** | Staff + Component Owner/Application Owner exceeds generic Berufserfahrene level; role may be lateral/down-level despite meaningful build scope |
| Recency and depth | 10 | **8** | Data/Kubernetes/Python current; direct production-ML integration and deepest Linux automation date to Bosch, while current LLM evidence is configuration-level |
| Domain/tool transfer | 10 | **6** | Strong transfer from Kubernetes, Linux, data platforms and inference deployment; compute cluster, GPU operations, RAG and search are not substitutable by wording |
| Practical constraints | 5 | **3** | Thun, German, 80-100% and work authorization are excellent; compensation and project-specific PSP access remain unresolved |
| **Total** | **100** | **74** | Numerical Adjacent; strategic **Stretch** because both title-leading AI/LLM responsibilities are not Direct |
## Competitive Read
- **Obvious-fit candidate:** an MLOps/LLM-platform engineer who has built a private RAG platform, operates GPU/compute clusters, implements retrieval/connectors in Python, and can pass RUAG's PSP; ideally also Swiss military officer/NCO background.
- **Dennis's advantage:** unusually strong combination of production data engineering, Kubernetes delivery, professional Linux/Ansible automation, containerized ML inference in 24/7 manufacturing, current LLM configuration/API exposure, native German, exact Thun location and verified officer career.
- **Their advantage:** direct ownership of the two things the title names: an AI/LLM platform and production retrieval/LLM solutions, plus likely GPU cluster depth.
- **Level/scope:** Dennis is currently Staff/Engineer IV. This vacancy is labelled only Berufserfahrene, not Senior/Staff/Principal. The platform build could be substantive, but compensation and decision authority must be checked before treating it as lateral rather than a down-level move.
## Framing Strategy if the user overrides the HOLD
- **Professional identity:** Staff Data & Platform Engineer with production ML-inference integration, Kubernetes/Linux automation and a six-year officer career.
- **Strongest proof points:** BS-1, BS-6, SW-3, SW-2, SW-1/SW-7, BW-1.
- **Honest adjacent bridges:** SW-8 and LiteLLM/API exposure for LLM context; FC-2/BS-4 for AI/R&D PoCs.
- **Explicit gaps:** no owned AI/LLM platform, no RAG/retrieval implementation, no compute/GPU cluster operation, no formal LLM evaluation, no model training ownership.
- **User directives:** officer career should be visible because the JD explicitly lists it as advantageous; no invented clearance, command scope or military ICT work.
## Cover Letter Decision
- **Provisional decision: YES if proceeding.** The portal makes it optional, but the officer-career motivation and the honest transition from data/MLOps infrastructure into an AI/LLM-platform remit add information the resume cannot fully carry.
- **Verified hooks:** only the live RUAG posting: C5I support to the Swiss Army/Kommando Cyber, DevSecOps model, sovereign/high-security systems and the Thun C5I campus.
- **Do not write yet:** Phase 0 is on HOLD.
## Questions that clear the HOLD
1. **Technical scope to Marco Heinzen:** Is direct production experience implementing RAG/LLM platforms expected on day one, or is the team explicitly hiring a strong Python/Kubernetes/data-platform engineer to build that capability?
2. **Compensation to Frank Haugwitz:** What is the target base-salary range for this vacancy, including how the 13th salary and variable allowances are quoted?
3. **PSP/project access to Frank Haugwitz:** Is a German citizen with a Swiss B permit eligible for the required PSP and all intended C5I project assignments?
4. **Level:** What decision authority and technical ownership distinguish this role from RUAG's Senior/Principal engineering roles?
## Phase 2: Audience and Content Plan
### Positioning and format
- **Profile:** Swiss/DACH, German, two pages. RUAG is a traditional Swiss defence employer and the portal requests a complete dossier.
- **Professional identity:** Staff Data & Platform Engineer with production ML-inference integration, Kubernetes/Linux automation, current hands-on LLM application configuration and a six-year Bundeswehr officer career.
- **Accuracy boundary:** Do not present Dennis as an established AI/LLM-platform owner. Do not claim RAG, retrieval implementation, GPU/compute-cluster operation, model training, formal LLM evaluation or a security clearance.
- **Headline direction:** `Staff Data & Platform Engineer | Python · Kubernetes · MLOps`
- **Summary:** YES, two short sentences. Lead with current Staff-level data/platform ownership and production ML-inference deployment; add the officer career as defence-context differentiation. Describe LLM work as configuration of domain-grounded assistants, not production platform engineering.
### Skills plan, five compact lines
1. **Programming and interfaces:** Python, SQL, REST APIs; LiteLLM only as current hands-on API exposure.
2. **AI/ML engineering:** ML-inference deployment, containerized AI workloads, domain-grounded LLM assistant configuration, applied NLP/speech-recognition contribution.
3. **Platform and automation:** Linux, Docker, Kubernetes, Ansible, GitLab CI/CD, Jenkins.
4. **Data engineering:** Kafka, Airflow, PySpark, AWS S3/Glue/Athena with Iceberg/Redshift.
5. **IaC, operations and security:** CloudFormation, ELK, Grafana, Prometheus; DevSecOps tied to the 2025/2026 Security Champion assignment, not presented as a certification.
TensorFlow/Keras remain certification-context only. C++, JavaScript, Terraform, RAG frameworks and named LLM orchestration libraries are omitted.
### Planned resume bullets
| Order | Role / claim | Evidence type | Scoped bullet direction | Why it belongs |
|---:|---|---|---|---|
| 1 | Swisscom, **SW-8** | Hands-on, current | Configured domain-grounded LLM assistants in a Swisscom-owned interface by selecting available models and supplying curated knowledge for Q&A, migration assistance and data mapping. | Closest current LLM evidence; directly relevant without implying RAG or deployment ownership. |
| 2 | Swisscom, **SW-3** | Production, current; primary developer/operator | Develops, deploys and operates Python data applications on Kubernetes; automates build, test and deployment through GitLab CI/CD. | Direct match for Python, Kubernetes, containerization and automation. |
| 3 | Swisscom, **SW-7** | Production, current; scoped data-product delivery | Models and implements governed data products and source onboarding within Swisscom's company-wide AWS Data Mesh; uses Compass for metadata and lineage as a practitioner. | Shows reliable data foundations for internal AI solutions while preserving shared-platform scope. |
| 4 | Swisscom, **SW-2** | Production, current; Component Owner | Holds component responsibility for Fulfillment pipelines from Oracle/Kafka into Teradata, including governance, support, on-call duty and SLA accountability. | Strongest operations and ownership evidence. |
| 5 | Swisscom, **SW-5** | Current bounded team assignment | Serves as team Security Champion for 2025/2026 after 100 hours of DevSecOps/security training and assessment. | C5I and the posting's DevSecOps context justify the otherwise optional signal. |
| 6 | Bosch, **BS-1** | Production, historical; primary integration owner | Integrated containerized ML inference with Docker, Kubernetes and Ansible into 24/7 semiconductor production, enabling fully automated image classification. | Flagship direct evidence for deployment and automation of AI workloads. |
| 7 | Bosch, **BS-6** | Production, historical; primary administrator/automation developer | Administered and automated Linux hosts for analytics and ML workloads; developed Ansible extensions and CI-triggered configuration workflows. | Closest evidence for the platform/compute side of the target role; no cluster scale is claimed. |
| 8 | Bosch, **BS-3** | Production, historical; Application Owner | Owned lifecycle responsibilities for analytics applications and upstream pipelines, including SLOs, documentation, training and vendor coordination. | Direct operational ownership plus the JD's documentation and knowledge-transfer requirements. |
| 9 | Bosch, **BS-4** | Proof of concept | Implemented an ELK/Kafka anomaly-detection PoC with Grafana, Prometheus and Loki monitoring. | Direct evidence for AI/R&D PoCs and observability; PoC status stays explicit. |
| 10 | Fraunhofer, **FC-2** | Research-project contribution | Implemented ML/NLP components within the ARTUS research team for automatic transcription of sea-rescue communications. | Adds applied NLP and research-pilot evidence; team scope avoids sole-ownership implication. |
| 11 | Vizrt, **VZ-1 + VZ-2** | Production, historical; primary developer | Developed Python backend components for distributed video transcoding and integrated automated A/V tests as CI/CD quality gates. | Concise software-engineering and DevOps depth; avoids irrelevant C++/JavaScript skill padding. |
| 12 | Bundeswehr, **BW-1** | Verified completed service | Completed officer candidate training and officer school during six years of Bundeswehr service; left service as Second Lieutenant. | Explicit preferred qualification and the package's strongest defence-context differentiator. |
Generali remains a compact chronology entry without bullets. **Capgemini is omitted entirely** by standing user preference (six months only; short-stay impression). The Bundeswehr receives a dedicated `Militärischer Werdegang` section rather than being hidden under additional information.
### Certifications and education
- M.Eng. Computer Aided Engineering and B.Eng. Information and Telecommunication Technologies remain visible.
- Highlight AWS Certified Solutions Architect - Associate, Data Engineering with AWS and IBM AI Engineering. TensorFlow/Keras appear only within the IBM certification context.
- iSAQB CPSA Foundation may be retained if layout permits; certifications appear exactly once.
### Impact and verification
- No unverified numeric metric is planned.
- `BS-1` may use the source-backed qualitative outcome of fully automated image classification; no percentage, scale or exact workload reduction will be invented.
- Optional enrichment, not required for generation: verified adoption/users or deployment status of the `SW-8` assistants. Without it, the bullet remains configuration-level.
### Cover Letter Decision
- **YES.** The optional letter adds two things the resume cannot fully explain: the deliberate, honest bridge from data/MLOps infrastructure into an AI/LLM-platform remit, and the motivation to contribute again in a defence-related environment after six years of Bundeswehr service.
- **Narrative:** production-critical ML integration at Bosch; current Kubernetes/data/LLM-adjacent work at Swisscom; officer background and motivation to support sovereign, secure C5I capabilities in Thun.
- **Boundary:** RUAG supports the Swiss Army; employment at RUAG must not be described as rejoining the armed forces. Use `erneut im Umfeld von Landesverteidigung und gesellschaftlicher Verantwortung wirken` rather than `wieder Teil der Armee sein`.
## Phase 3/4: As-built Resume
- **File:** `output/RUAG_AI_Engineer_C5I/e2e_ruag_ai_engineer_c5i_resume.tex`
- **Format:** German Swiss/DACH profile, A4, 11 pt, two pages, no photo.
- **As-built positioning:** `Staff Data & Platform Engineer | Python · Kubernetes · MLOps`.
- **As-built selection:** 12 bullets using `SW-8`, `SW-3`, `SW-7`, `SW-2`, `SW-5`, `BS-1`, `BS-6`, `BS-3`, `BS-4`, `FC-2`, `VZ-1 + VZ-2` and `BW-1`. Generali remains an unbulleted chronology entry. Capgemini is omitted.
- **Military evidence:** `BW-1` appears in the profile and in a dedicated `Militärischer Werdegang` section. No command responsibility, deployment, clearance or military ICT work is implied.
- **LLM boundary:** current evidence is stated as configuration of domain-grounded assistants and LiteLLM API use. The document contains no RAG, retrieval, compute-cluster, GPU-cluster, model-training or LLM-platform ownership claim.
- **Plan adjustment for layout:** certifications appear once inside `Kenntnisse`; German and English appear in the header. This preserves the information and gives page 2 a cleaner close. The Bosch title was shortened to the verified formal title to avoid a collision with the location.
- **Language sweep:** no em dash, `Baue`, `Trug`, `begrenzt`, C++, JavaScript, Terraform, RAG or fabricated orchestration framework appears. Bullets use technical, scoped verbs.
### Validation and rendering
- Canonical system preflight: **PASS, 0 warnings**.
- Document validator after final edit: **PASS, 0 warnings**.
- MiKTeX compilation: **PASS**, two runs, exactly **2 pages**.
- Log inspection: no Overfull/Underfull boxes and no LaTeX/package warnings.
- `pdftotext -layout`: employer, title, date, location and section order parse correctly across both pages.
- Visual QA: both final pages rendered to PNG at 150 dpi and inspected; no clipping, overlap, broken glyphs, isolated headings or awkward page transition.
- The compiled PDF and PNGs were temporary QA artifacts only. The deliverable remains the `.tex` source as configured.
## Post-Handover Fix and Re-Verification, 2026-08-27
The package was inherited mid-session after a usage limit on the previous model. The recorded Phase 3/4 completion was audited independently and one defect was found and corrected.
### Defect found and fixed
- **Capgemini Deutschland GmbH was present as a chronology entry.** This violates a standing user preference recorded in `CLAUDE.md` and in memory: Capgemini is omitted from all documents because the six-month tenure reads as a short stay. A corpus check confirmed this resume was the **only** generated `.tex` under `output/` containing Capgemini. The entry and its separating vertical space were removed; the visible chronology now begins at Generali, Mai 2015.
- **The Nov. 2014 to Mai 2015 gap this creates is intentional and stays.** The submitted Kdo Cy resume carries the identical gap.
- **The profile claim "über zehn Jahren" survives unchanged.** The visible record now runs Generali Mai 2015 to Aug. 2026, about eleven years three months, so the wording remains true.
### Re-verification after the fix
- Document validator: **PASS, 0 warnings** (re-run after the Thun contact-line change).
- MiKTeX compilation, two runs: **PASS**, exactly **2 pages**, **0 Overfull/Underfull boxes**, no LaTeX or package warnings. Re-run after the Thun change, this time **compiled into the output folder** rather than a temp directory.
- Extracted text of the final PDF contains **0** occurrences of "Capgemini" and reads `Thun, Schweiz` in the contact line.
- Text extraction: employer, title, date, location and section order parse correctly on both pages; footers read 1/2 and 2/2.
- Visual QA: both pages re-rendered to PNG and inspected **after** the edit. No clipping, overlap, orphaned heading or broken page transition. Page 2 closes on Ausbildung with roughly two inches of trailing whitespace, which is accepted; `CLAUDE.md` forbids page-fill quotas.
- **Note on the prior session's QA claim:** the temporary working folder still held a stale 3-page text extraction from an earlier draft, so the previously recorded visual check was made against a different document than the final one. The checks above were run against the current source.
- **Page 2 was deliberately not backfilled.** `PP-3` (private Debian server) is available as additional Linux evidence and was used in the Kdo Cy package, but re-opening the approved 12-bullet plan to fill freed space would be page-filling, not relevance.
### Contact location: RESOLVED 2026-08-27
- **The contact line was changed from `Bern, Schweiz` to `Thun, Schweiz`.** The user decided on 2026-08-27 that for roles **in Thun and its immediate surroundings** the contact line may carry Thun. This vacancy is in Thun and the user lives in Thun, so local residency is now visible to a traditional Swiss defence employer - the session's Competitive Read already counted "exact Thun location" among his advantages, and the document had been hiding it.
- **Scope of the change:** contact line only. The Swisscom position keeps `Bern, Schweiz`, because that is factually where that job is.
- **Recorded as a standing rule** in memory and `config.md`: Thun for Thun-area roles, Bern as the default everywhere else. The earlier "always Bern, ask first" note is superseded.
## User Review Round, 2026-08-27
Three changes requested by the user on review of the compiled PDF. All three applied, then re-validated, re-compiled and both pages re-inspected.
| # | Change | Basis |
|---|---|---|
| 1 | **Removed "Kein Sponsoring durch den Arbeitgeber erforderlich" from the contact line.** | User: it is common knowledge that EU citizens need no sponsorship, so the sentence adds nothing. The header still carries "Deutscher Staatsbürger" and "Schweizer Aufenthaltsbewilligung B", which resolve work authorization on their own. |
| 2 | **Bosch title changed to `Senior Data Engineer, Data Analysis (Beförderung Jan. 2021)`**, matching the Swisscom line's shape. | The promotion is **not** in `claims.json`; it is recorded LinkedIn-confirmed in `experience_bosch.md`: Data Engineer Feb 2020 - Jan 2021, **Senior** Data Engineer Jan 2021 - Dez 2022. That file also explicitly sanctions "(Senior) Data Engineer" as a display form. `claims.json` has now been corrected so this is canonical going forward. |
| 3 | **Vizrt title shortened to `DevOps Engineer`**, dropping "Test Automation /". | User request. ⚠ **Flagged accuracy note:** the canonical `official_title` for Vizrt is **"Test Automation Engineer"**; "DevOps Engineer" is half of the sanctioned `display_title` "Test Automation / DevOps Engineer". The bullet content (CI/CD quality gates, Python backend for distributed transcoding) supports the DevOps framing, and the user is the authority on his own role, but this is the one title line on the document that will not match a Zeugnis or reference check word-for-word. Recorded here so it is a conscious choice, not a drift. |
### Re-verification after the review round
- Document validator: **PASS, 0 warnings**.
- MiKTeX, two runs: **PASS**, exactly **2 pages**, **0 Overfull/Underfull boxes**, no LaTeX or package warnings.
- Both pages re-rendered and inspected. The longer Bosch title does **not** collide with `Dresden, Deutschland`; the earlier concern recorded in `CLAUDE.md` about a Bosch title/location collision does not apply at this length.
- Header now reads three lines: contact, citizenship/permit, languages.
- Build artifacts removed from the output folder; `Dennis_Thiessen_Lebenslauf.pdf` refreshed from the new build and verified identical to the `e2e_` PDF by checksum.
## Phase 5: As-built Cover Letter, 2026-08-27
- **File:** `output/RUAG_AI_Engineer_C5I/e2e_ruag_ai_engineer_c5i_cover_letter.tex`
- **Format:** German Swiss/DACH motivation letter, A4, 11 pt, **1 page, 275 body words** (target 250-300).
- **Addressee:** Frank Haugwitz, Director Sourcing C5I-Campus, at RUAG MRO Holding AG, Business Area C5I, Uttigenstrasse 36, 3600 Thun. Submission is portal-only; the letter is uploaded, not mailed.
- **Contact location:** `Thun, Schweiz`, consistent with the resume and the new Thun-area rule.
- **Structure:** four short paragraphs plus close. (1) Role thesis: the posting pairs operating an internal AI-workload platform with building the pipelines those workloads depend on, which is the seam he already works on. (2) Bosch `BS-1` and `BS-6`. (3) Swisscom `SW-3`, `SW-2`, then the LLM boundary. (4) `BW-1` and practical fit.
### Deliberate decision: the LLM gap is named explicitly
The letter states plainly *"Eine AI-Plattform habe ich nicht aufgebaut"*, then pivots immediately to the operations/platform side and to working toward the implementation side from there.
This is a conscious departure from the Kdo Cy letter's approach, where the second-Amtssprache point was deliberately **not** raised so as not to hand the reader an objection (the Aker BP CL-A finding). The reasoning for treating this case differently:
- The AI/LLM-platform build is **R1, the title-defining responsibility and the JD's first bullet**, not a peripheral requirement. The reader will assess it whether or not the letter mentions it, so silence does not remove the objection - it only removes his framing of it.
- The session's own Cover Letter Decision names this bridge as the letter's reason to exist: the resume cannot carry it.
- The JD explicitly invites applicants who do not meet every requirement, which makes candour read as judgement rather than as a defensive gap list.
- It is one sentence, immediately followed by what he does bring. It is not a gap list.
**Reversible.** If the user prefers the Kdo Cy posture, the sentence can be cut and the paragraph still stands on `SW-3`, `SW-2` and `SW-8`.
### Claim traceability
Every claim in the letter maps to a resume bullet and a canonical ID: `BS-1` (containerized ML inference into continuous semiconductor production), `BS-6` (Linux administration, Ansible extensions, credential-caching plugin), `SW-3` (Python data applications on Kubernetes), `SW-2` (Component Owner, Oracle/Kafka to Teradata, on-call), `SW-8` (configuring domain-grounded assistants; LiteLLM API use), `BW-1` (six years, officer training, Leutnant). No new skill, tool, metric, customer or ownership claim is introduced.
### Boundaries verified in the body text
Automated scan of the letter body (comments excluded) found **0** occurrences of RAG, Retrieval, GPU, Compute Cluster, GitOps, LangChain, Terraform, fine-tuning, model training, clearance/Sicherheitsfreigabe, or "wieder Teil der Armee". The only regex hit was the substring "rag" inside *Abfragen*. **0** em dashes.
- RUAG is described as an environment of `Landesverteidigung und gesellschaftlicher Verantwortung`, never as rejoining the armed forces.
- `SW-8` stays configuration-level; no platform ownership, orchestration or evaluation is implied.
- `BS-1` claims integration, not model training.
- `BW-1` carries no clearance, command scope or military technical work.
- No unverified metric appears.
### Hook verification, 2026-08-27
All hooks are first-party, re-fetched live from the posting on the day of writing rather than trusted from the earlier retrieval.
| Claim in the letter | Evidence | Source |
|---|---|---|
| Role title `AI Engineer C5I (w/m/d)` | Verbatim match | jobs.ruag.ch posting, live 2026-08-27 |
| Legal entity `RUAG MRO Holding AG, Business Area C5I` | Verbatim match | same |
| Address `Uttigenstrasse 36, 3600 Thun` | Verbatim match | same |
| Addressee `Frank Haugwitz`, Director Sourcing C5I-Campus | Verbatim match, contact still listed | same |
| The role pairs an internal AI/LLM platform with pipelines/interfaces | `Aufbau, Weiterentwicklung und Betrieb einer internen AI-/LLM-Plattform inkl. Compute Cluster` | same |
| Posting status | LIVE, application form reachable | same |
No company-news, product or executive-statement hook was used. `cl_reference.md` prefers omitting an unnecessary hook over spending a paragraph proving company familiarity.
### Validation and rendering
- Document validator: **PASS, 0 warnings**.
- MiKTeX, two runs: **PASS**, exactly **1 page**, **0 Overfull/Underfull boxes**, no LaTeX or package warnings.
- Page rendered to PNG and inspected: single well-filled page, no clipping or awkward break.
- Build artifacts removed; `Dennis_Thiessen_Motivationsschreiben.pdf` created from the same build and verified identical by checksum.
## Critique, 2026-08-27
- **File:** `output/RUAG_AI_Engineer_C5I/critique_ruag_ai_engineer_c5i.md`
- **Evidence Fit: 74/100** - re-verified against `claims.json`, unchanged. Strategic **Stretch**; title-capability gate **FAIL** (R1 and R2 both Adjacent). PSP project access and compensation remain **UNRESOLVED**, which is independently a NO-GO trigger under `critique_framework.md` section 1. All of this was in front of the user at the 2026-08-27 override and is recorded, not re-litigated.
- **Document Quality: 85/100.** Truth and provenance **23/25** - well clear of the 8/10 automatic-failure floor.
- **Channel: Weak.** Cold portal submit; `jobs.ruag.ch` refuses email and post. Marco Heinzen's direct mobile is published and unused.
- **Scoring standard:** `critique_framework.md` governs over `SKILL.md` section 9.3/9.4 - dual score, verdicts instead of invented probabilities, no single overall score, no publications weight. `SKILL.md`'s additive coverage (domain lens, five-reader read, bridge points, 6A-6F) was kept in full.
### Verified independently, not inherited from this session file
Both documents re-validated (**PASS, 0 warnings**), recompiled twice in a scratch folder and found **byte-identical** to the shipped PDFs (133 673 B / 95 497 B), 2 pages / 1 page exactly, **0 boxes, 0 LaTeX warnings**, correct `pdftotext` order, both resume pages and the letter re-rendered at 130 dpi and inspected. Submission-named copies match their `e2e_` builds by **MD5**. `Capgemini` 0 hits; all global-forbidden patterns 0 hits.
### Full skills-token audit - the check that had not been run
Every token in the header, `Kenntnisse` block and letter was enumerated against `claims.json` `skills[].output`. **Zero `forbidden` skills on either document.** The two non-plain-`allowed` tokens present both carry their required context: **LiteLLM** (`allowed-with-context`) as "in aktueller API-Nutzung", **TensorFlow/Keras** (`certification-context-only`) only inside the Zertifizierungen line. Tokens absent from `skills[]` (Grafana, Prometheus, Loki, Jenkins, GitLab, ELK, Teradata, Oracle, Glue, Athena, Iceberg, Redshift, S3, MLOps) are all claim-backed or experience-file-backed - `skills[]` is a control list, not an inventory. **No Tier 1 truth finding anywhere in the package.**
### Tier 1 fixes - 3, none reopens the bullet plan's truth boundaries
(Tier 1 ranks by **submission impact**, not strictly by point value: T1-1 scores under cover-letter tailoring, which section 3 does not weight.)
1. **The letter drops DevSecOps, C5I, Kommando Cyber and the Army.** The JD's `Ueber den Bereich` block leads with all four and states "konsequent nach dem DevSecOps-Modell". `SW-5` is on the resume - Security Champion 2025/2026 after 100 h of Cloud Security / DevSecOps / Security by Design training - and the letter never uses it. A first-party hook matched by current canonical evidence, left on the table. One sentence closes it. **Highest-value edit in the package.**
2. **`PP-3` is missing and it is the only *current* evidence for the operating half of the role.** The letter's load-bearing sentence is *"Was ich mitbringe, ist die Betriebs- und Plattformseite dieser Rolle"*, and its resume proof is `BS-6`, which **ended Dec 2022**. `claims.json` calls PP-3 "the primary evidence for hands-on Linux administration, system hardening and security configuration, and it is current and continuous". For a defence employer screening every entrant, a decade of self-hosting *and hardening* is materially different, and it evidences Q6 better than any employer bullet. **This is a relevance argument, not page-filling** - section 7a's whitespace ban is not the basis. Kdo Cy used PP-3; this package dropped it.
3. **`governte Datenprodukte` is not a German word** - the only outright language error in the package. German IT does form participles from English verbs (*gemanagt*, *gehostet*), but *governt* is not among them, and the reader is a native-German Swiss engineer. A corpus check confirms it is a **one-off**: it appears in no other generated document, and **the user's own submitted Kdo Cy CV already carries the fix** - "Modelliere **governance-konforme** Data Products". A one-word substitution, independent of the other two, **worth taking regardless of what is decided about them**. It carried a full point of the Mechanics deduction on its own, separate from cadence.
### Tier 2 (6)
- **The headline drops "AI" from a req titled AI Engineer**, while his canonical title "Staff Data, Analytics & **AI** Engineer" contains it. Deliberate session choice, not reversed; middle option `Staff Data, Analytics & AI Engineer | Python - Kubernetes - MLOps` uses his real title and promises no platform ownership. **User's call.**
- **Four honestly closeable JD terms absent:** Data Preprocessing/Datenaufbereitung, Wissenstransfer, AI-Workloads, Containerisierung. Leave MVP/Pilotloesung - PoC is what the evidence supports.
- **`IBM AI Engineering` has no primary-source record.** The other three certs are in `thiessen_certifications.md` with issuer, date, expiry and cert number; this one is only in `bundle_ml_ai_engineer.md`. Same class as the Ansible/Linux/Bosch-promotion gaps - **verify and record, do not remove**. It matters because TensorFlow/Keras is the *sole* answer to the JD's required "moderne ML-/AI-Frameworks".
- **CL paragraph 2 is ~90 of 275 words re-telling BS-1 and BS-6**, redeemed by one genuinely new sentence. Compressing it frees the words the two Tier 1 fixes need.
- **The pivot after the gap admission concedes without evidence** - *"die Implementierungsseite wuerde ich mir von dort aus erarbeiten"* promises to learn. The gap sentence itself is a sound call and should stay; anchor the pivot in BS-1/FC-2.
- **Volunteering foreign citizenship in the letter at a PSP employer.** Already in the resume header. Lean keep (the sentence lands on "ich wohne in Thun, also am Standort selbst"), but a conscious choice.
### Tier 3
Cadence: 6/12 bullets end in a 3+ list, exactly at the section 7a ceiling, with consecutive triples at B1-B2 and B8-B9; **bullets 9 and 10 both open "Implementierte"**, a direct section 7a hit that the validator missed because its check does not cross position boundaries. `\today` in the letter - recompile if submitted after 2026-08-27. Bottom whitespace is **not** a finding (section 7a bans adding content for it). Thesis grade 1,0 is permitted; keep.
### Reader verdicts
ATS **PASS** - clean extraction. Recruiter (Haugwitz) **FORWARD** - every box he owns is above the fold. HR **COMPLETE**. Hiring manager (Heinzen) **MAYBE, and the letter decides it** - if the brief is "build our RAG stack" this is a no; if it is "run the platform while we grow the AI layer" it is a strong yes. Technical reviewer **CREDIBLE** - no claim collapses; first probes are the SW-8 boundary, compute-cluster scale, the 2008-2014 / 2009-2013 officer-track overlap, and Pull-GitOps.
### Cover letter decision
**KEEP.** The resume structurally cannot answer what this candidate thinks he is applying for given what he has not done; the letter does, in his own words, before Heinzen has to infer it. It needs T1-1 and T2-6.
## Edit 1 Baseline, 2026-08-27
- **Pages:** 2 (exact)
- **Validator:** PASS, 0 warnings
- **Overfull/Underfull boxes:** 0 | **LaTeX warnings:** 0
- **Variable bullets:** 12 (Swisscom 5, Bosch 4, Fraunhofer 1, Vizrt 1, Bundeswehr 1)
- **Skills lines:** 6 (incl. Zertifizierungen)
- **Char violations:** none - `CLAUDE.md` and `resume_reference.md` sections 4/7 replaced fixed 1L/2L/3L bands with natural-length bullets; character counts are diagnostic only and there is no page-fill quota, so the skill's "all bullets must be 2L" and "<=3 lines white space" gates do **not** apply to this project.
- **Orphan violations:** none observed in visual QA
- **White space:** ~2 in at the foot of both pages, accepted per `resume_reference.md` section 7a ("Do not add content merely to reduce bottom whitespace")
- **Cover letter:** 1 page, 275 body words, 4 paragraphs + close, validator PASS
### Edit 1 (2026-08-27): critique Tier 1 + Tier 2, user-approved
**Source:** `critique_ruag_ai_engineer_c5i.md`, user instruction 2026-08-27 ("apply 1-5, 6: use my official title, 7: cut").
**Resume**
| # | Change | Class | Source |
|---|---|---|---|
| 1 | `governte` -> `governance-konforme Datenprodukte` | MODIFY | T1-3 |
| 2 | New `Projekte` section: `Privater Debian-Server / seit rund zehn Jahren / Eigenbetrieb`, one bullet (`PP-3`) | ADD | T1-2 |
| 3 | Headline and profile opener -> **`Staff Data, Analytics & AI Engineer`**, his canonical title | MODIFY | T2-2, **user chose the official title** |
| 4 | `Wissenstransfer`, `Datenaufbereitung`, `AI-/ML-Workloads` + `Containerisierung` added where the work is real | MODIFY | T2-3 |
| 5 | Bullet 9 opener `Implementierte` -> `Baute` | MODIFY | Tier 3 (7a) |
| 6 | BS-3 list reordered to natural German: `koordinierte Hersteller, technische Dokumentation und Wissenstransfer an die Nutzer` | MODIFY | found during visual QA |
**Cover letter**
| # | Change | Class | Source |
|---|---|---|---|
| 7 | New standalone paragraph naming **DevSecOps and C5I**, carried by `SW-5` (Security Champion 2025/2026, 100 h) | ADD | T1-1 |
| 8 | Paragraph 2 compressed: the Ansible credential-plugin detail re-told resume bullet 7 | MODIFY | T2-5 |
| 9 | Pivot anchored in evidence: `erarbeite ich mir von dort aus, wie zuvor bei der ML-Inferenz in Dresden` | MODIFY | T2-6 |
| 10 | **Volunteered citizenship sentence cut** | REMOVE | T2-7, **user chose cut**. The resume header still carries `Deutscher Staatsburger` and `Schweizer Aufenthaltsbewilligung B` |
| 11 | Paragraph 3 split so the DevSecOps beat stands alone | MODIFY | found during visual QA - the merged paragraph ran to nine lines and carried three jobs |
### Two defects found during this edit that the critique had not caught
1. **The resume never loaded `babel`, so a German document was being hyphenated with English patterns.** Visible in the compiled PDF as `Hal-bleiterfertigung`, `Tran-skription` and `automa-tisierte`. Present at baseline and inherited by every earlier build. Adding `\usepackage[ngerman]{babel}` fixed the hyphenation (`Halb-leiterfertigung`, `automati-sierte`) **and** cleared the one overfull box that the longer headline had introduced. A `\hyphenation{Trans-krip-ti-on}` exception was added because ngerman still broke `Transkription` after `Tran`. **Worth checking on every future German-language package.**
2. **A one-box regression appeared and was caught by the gate, not by eye:** the longer official title reflowed the profile paragraph and overflowed by 33.6 pt. Fixed by the babel change above, not by rewording.
### Verification after Edit 1
| Gate | Resume | Cover letter |
|---|---|---|
| Canonical validator | **PASS, 0 warnings** | **PASS, 0 warnings** |
| MiKTeX, two passes | **PASS** | **PASS** |
| Pages | **2** (unchanged) | **1** (unchanged) |
| Overfull/Underfull boxes | **0** | **0** |
| LaTeX warnings | **0** | **0** |
| Submission copy refreshed + MD5 match | **yes** | **yes** |
| Visual QA at 130 dpi | both pages re-rendered and inspected | re-rendered and inspected |
- **CL body words: 295** (target 250-300). Five short paragraphs plus close.
- **Cadence improved:** list-terminated bullets **6/12 (50%) -> 4/13 (31%)**, comfortably under the 7a ceiling; **consecutive identical openers 1 -> 0**.
- Forbidden sweep across both `.tex` files and both extracted PDFs: **0 hits** for Capgemini, LangChain/LangGraph/LlamaIndex, Terraform, Azure, GCP, GitOps, TypeScript, FastAPI, Flask, Django, every global-forbidden pattern, and the standalone acronym `RAG` (the only `rag` matches are inside *Fragen* and *Abfragen*). **0 em dashes.**
### Baseline comparison
| Metric | Before | After | Delta |
|---|---:|---:|---|
| Pages | 2 | 2 | 0 |
| Bullets | 12 | 13 | +1 (`PP-3`, inside the 11-14 guide) |
| Boxes | 0 | 0 | 0 |
| Validator warnings | 0 | 0 | 0 |
| List-terminated bullets | 50% | 31% | **-19 pts** |
| Consecutive identical openers | 1 | 0 | **-1** |
| CL body words | 275 | 295 | +20 (in range) |
| German hyphenation | English patterns | **ngerman** | fixed |
### KB corrections made during this edit
- **`IBM AI Engineering` verified and recorded.** The user supplied the certificate; it was read directly. IBM via Coursera, **4 Jun 2020**, no expiry, verify code `3ZBZFVAL6A34`, name on certificate `Dennis Thiessen` (ss/sz variant, as on ITIL and iSAQB). Added as entry **#8** in `thiessen_certifications.md`. **T2-4 is closed** - the resume's `IBM AI Engineering mit TensorFlow/Keras` line is now backed by a primary source, which matters because it is the sole evidence for the JD's required *moderne ML-/AI-Frameworks*.
- **`PyTorch` upgraded in `claims.json`** from `coursework-or-personal-unverified` to `evidence: certification`. The same certificate includes *Deep Neural Networks with PyTorch*. `output` stays `certification-context-only`, so this changes nothing on any current document - it just means PyTorch now has a real source if a JD ever asks. Patched as text, not re-serialized, per the CRLF/compact-JSON note in `CLAUDE.md`.
- The certificate is explicitly **non-credit** and confers no grade or degree; never present it as an academic qualification.
## Critique Round 2, 2026-08-27 (post-Edit 1)
- **File:** `critique_ruag_ai_engineer_c5i.md`, rewritten as Round 2 with a Round 1 resolution table.
- **Evidence Fit: 74/100 - unchanged.** Strategic Stretch, title-capability gate **FAIL**, PSP and compensation **UNRESOLVED**. Document edits cannot move candidate-role fit. **`PP-3` deliberately did not move it**: it is a personal project and cannot convert an Adjacent title-capability into a Direct one - counting it would be the "bridge valued as highly as direct evidence" error `critique_framework.md` section 5 warns against.
- **Document Quality: 85 -> 93/100.** Truth and provenance **23 -> 24/25**.
- **Channel: Weak - unchanged.** Heinzen's published direct line still unused.
- **Tier 1 findings: NONE.** No truth, fit or relevance defect remains that editing can fix.
### Dimension movement
| Dimension | R1 | R2 | Why |
|---|---:|---:|---|
| Truth and provenance | 23 | **24** | IBM cert primary-source verified; new PP-3 and SW-5 content audited clean; headline now his real title, not a positioning label |
| Information hierarchy | 17 | **19** | Headline carries the req's word above the fold; `Projekte` parses cleanly |
| Bullet evidence and impact | 16 | **16** | **Unchanged - now the weakest dimension** |
| Relevance and terminology | 12 | **15** | 22/22 claimable JD terms; all six gap terms still correctly absent |
| Skills evidence | 9 | **9** | Unchanged; `MLOps` remains an umbrella term with no `skills[]` entry |
| Mechanics/readability | 8 | **10** | `governte` fixed, German hyphenation fixed, cadence 50%->31%, consecutive openers 1->0 |
### Reader verdicts
ATS **PASS**. Recruiter **FORWARD** - the Round 1 friction point is gone, the headline now shows the req's own word. HR **COMPLETE**. Hiring manager **still MAYBE, but a stronger MAYBE** - the underlying R1/R2 split is unchanged; the letter now argues the operating-layer case more completely. Technical **CREDIBLE**, with a new and welcome probe invited by PP-3: "what have you actually hardened, and how do you patch it?"
### The one dimension that did not move
**Bullet impact: 12 of 13 bullets describe activity with no outcome clause; only `BS-1` says what changed.** Every other claim in `claims.json` carries `metrics: unverified`, and inventing figures is barred - so the resume is correctly written but flat where a hiring manager looks for consequence. **The fix is upstream, not in this package:** if any verified outcome exists for `SW-2` (incident/SLA record), `SW-3` (deployment frequency, service count), `SW-7` (data products delivered, sources onboarded) or `BS-3` (applications owned), recording it in `claims.json` would lift this dimension for **every** future package. Do not invent anything to close it here.
### Remaining Tier 2 / Tier 3
Officer career still on page 2 (structural; moving it breaks reverse chronology). Headline now duplicates the Swisscom title line verbatim (cosmetic). The CL's *"entspricht damit meiner heutigen Praxis"* is a soft alignment claim worth being ready to answer, not worth rewording. Bosch bullet lengths cluster at a 5-word spread (validator passes; diagnostic only). `\today` - recompile if submitted after 2026-08-27.
## SUBMITTED 2026-08-27
Application sent via `jobs.ruag.ch` (portal only - email and postal applications are explicitly refused).
Application ID **18027**, publish ID 10075372.
### As-submitted record
| Field | Value |
|---|---|
| Employer | RUAG MRO Holding AG, Business Area C5I |
| Role | AI Engineer C5I (w/m/d), Thun, 80-100% |
| Submitted | **2026-08-27** |
| Fit class | **Stretch** (numerically top-of-Adjacent at 74) |
| Evidence Fit | **74/100** |
| Hard gate | **FAIL** - R1 and R2, the two title-defining responsibilities, are Adjacent not Direct |
| Document Quality | **93/100** (85 pre-edit), truth and provenance 24/25, **0 Tier 1 findings** |
| Channel | **Weak** - cold portal submit |
| Cohort | evidence-first-2026-01, now **6/10**; **the sole Stretch slot is CONSUMED (stretch 1/1)** |
| Outcome | applied - awaiting response |
**Submitted documents:** `Dennis_Thiessen_Lebenslauf.pdf` (2 pages, 13 bullets) and
`Dennis_Thiessen_Motivationsschreiben.pdf` (1 page, 295 words, 5 short paragraphs). Both validators PASS with
0 warnings, 0 boxes, clean two-pass compiles, correct text-order parse and visual QA of every page. Submission
copies were MD5-verified identical to their `e2e_` builds before sending.
### What went in, in one line
Staff Data, Analytics & AI Engineer - his canonical title - with production ML-inference integration (`BS-1`),
professional Linux/Ansible automation (`BS-6`), current Kubernetes and data-product work (`SW-3`, `SW-7`, `SW-2`),
current self-hosted Linux and hardening (`PP-3`), DevSecOps practice tied to C5I's stated operating model (`SW-5`),
and the canonical six-year Bundeswehr officer career (`BW-1`). The letter names the AI-platform gap in one sentence
and pivots to the operations and platform side.
### Live screening topics - none of these were resolved before sending
1. **Compensation.** No band published. Kununu samples are small and non-authoritative but suggest a material cut
against the ~CHF 140k current and the 180k bar. The Thun-local exception permits near-current pay, not a large
reduction. **Ask Frank Haugwitz.**
2. **PSP and project access.** RUAG screens every entrant. No citizenship requirement is stated and German
citizenship plus a Swiss B permit is not an evidenced disqualifier, but role-specific project eligibility is
unknown. **Ask Frank Haugwitz.**
3. **Level.** The req is labelled only "Berufserfahrene" and may be lateral or a down-level move against current
Staff + Component Owner scope. **Ask what decision authority separates this from RUAG's Senior/Principal roles.**
4. **The question the application actually turns on:** does C5I want someone who has *built* an AI/LLM platform, or
someone who can *operate* one and grow into building it? **Marco Heinzen, +41 79 568 14 96** - the published
direct line that was never used. A call now would still upgrade the channel from Weak to Moderate.
### Honest gaps that travel with this application
No AI/LLM platform built or operated; no compute or GPU cluster; no RAG, retrieval or document-solution
implementation; no formal LLM evaluation; no model-training ownership. ML/AI-framework depth is certification-context
only (IBM AI Engineering, now primary-source verified). These are real and were never written around.
### Standing note for any future RUAG C5I application
The KB now holds a verified, live JD and a full Phase 0 for this business area, and RUAG C5I has **five other reqs**
already in the scout log (Senior DevOps Engineer C5I and Data Lakehouse / Senior Data Platform Engineer are both
shortlisted and are **materially better fits than this one** - they sit on the DevOps/data-platform lane where his
evidence is Direct rather than Adjacent). If this application is rejected, that is **not** a signal to drop RUAG;
it is a signal to target the reqs that match the evidence. Note also that the cohort's Stretch slot is now full,
so any further RUAG application must clear Core or Adjacent on its own merits.
## Output Files
- Verbatim JD: `output/RUAG_AI_Engineer_C5I/JD_ruag_ai_engineer_c5i.txt`
- Session: `output/RUAG_AI_Engineer_C5I/session_ruag_ai_engineer_c5i.md`
- Resume: `output/RUAG_AI_Engineer_C5I/e2e_ruag_ai_engineer_c5i_resume.tex`; finished, Capgemini defect corrected, re-validated and re-compiled 2026-08-27; awaiting user approval.
- Compiled resume PDF: `output/RUAG_AI_Engineer_C5I/e2e_ruag_ai_engineer_c5i_resume.pdf` and a submission-named copy `output/RUAG_AI_Engineer_C5I/Dennis_Thiessen_Lebenslauf.pdf`, both built 2026-08-27 from the corrected source. ⚠ **`Dennis_Thiessen_Lebenslauf.pdf` is a copy, not a build target.** pdflatex only regenerates the `e2e_` file, so the submission-named copy must be **refreshed after every recompile** or it silently becomes the old version under the exact filename that would be attached to the application.
- Cover letter: `output/RUAG_AI_Engineer_C5I/e2e_ruag_ai_engineer_c5i_cover_letter.tex`, with `e2e_ruag_ai_engineer_c5i_cover_letter.pdf` and the submission-named `Dennis_Thiessen_Motivationsschreiben.pdf`. Built 2026-08-27; awaiting user approval.
- Critique: `output/RUAG_AI_Engineer_C5I/critique_ruag_ai_engineer_c5i.md` - **CURRENT**, written 2026-08-27. Evidence Fit 74, Document Quality 85, Channel Weak.
## Status
- **Phase 0:** COMPLETE 2026-08-27.
- **Fit gate:** Explicitly overridden by the user on 2026-08-27; strict hard-gate FAIL, Evidence Fit 74 and strategic Stretch remain recorded.
- **Phase 2:** COMPLETE; audience and 12-bullet content plan prepared.
- **Phase 3/4:** COMPLETE; resume generated, validated, compiled and visually inspected. **Re-audited after handover 2026-08-27:** one standing-preference defect (Capgemini) found and fixed, then re-validated, re-compiled and re-inspected. See Post-Handover Fix and Re-Verification.
- **Resume:** finished; awaiting user approval.
- **Phase 5 (cover letter):** COMPLETE 2026-08-27; generated, hooks verified live, validated, compiled and inspected.
- **Cover letter:** DONE; awaiting user approval.
- **Application/outcome:** **SUBMITTED 2026-08-27** via jobs.ruag.ch, application ID 18027. Awaiting response. Cohort recorded: Stretch slot consumed, cohort 6/10.
- **Contact location:** RESOLVED 2026-08-27 - `Thun, Schweiz`.
- **Resume:** approved by the user 2026-08-27 (implicitly, by invoking `/make-cl`), after three review changes: sponsoring sentence removed, Bosch title with promotion date, Vizrt shortened to DevOps Engineer.
- **Critique:** **CURRENT (Round 2, 2026-08-27, post-Edit 1)** - Evidence Fit **74/100**, Document Quality **93/100**, Channel **Weak**, **Tier 1 findings: none**. Round 1 (pre-edit) scored - Evidence Fit **74/100**, Document Quality **85/100**, Channel **Weak**, **no Tier 1 truth finding**, 3 Tier 1 fixes open (DevSecOps hook in the letter, PP-3 on the resume, `governte` -> `governance-konforme`).
- **Edit 1:** COMPLETE 2026-08-27. All three Tier 1 fixes applied, plus Tier 2 items 3-5 and the two user decisions (official title; citizenship sentence cut). Both documents re-validated, recompiled, re-rendered and inspected; submission-named PDFs refreshed and MD5-matched.
- **Next:** await response. Optional and still worthwhile: call **Marco Heinzen, +41 79 568 14 96** about technical scope and level, and **Frank Haugwitz** about compensation and PSP/project eligibility - all three are now live screening topics rather than pre-cleared ones. Do not react to a single rejection with positioning changes (`application_strategy.md` sections 38/74); the better-fitting RUAG C5I DevOps and Data Platform reqs are already shortlisted in the scout log. **Unchanged and unaffected by any edit:** Evidence Fit 74, Stretch, title-capability gate FAIL, and the open PSP / compensation / level questions. The highest-value remaining action is not a document change - it is the call to Marco Heinzen (+41 79 568 14 96). Compensation, PSP/project access and role level remain open practical questions and are unaffected by the documents. Because the cover-letter decision is YES, proceed with `/make-cl` after approval. Compensation, PSP/project access and level remain open practical questions.
+469 -75
View File
@@ -1,9 +1,15 @@
{ {
"schema_version": 1, "schema_version": 1,
"last_verified": "2026-07-27", "last_verified": "2026-08-27",
"authority": { "authority": {
"description": "Machine-readable source of truth for all future application documents.", "description": "Machine-readable source of truth for all future application documents.",
"precedence": ["canonical claims", "config corrections", "verified references", "experience files", "bundles"], "precedence": [
"canonical claims",
"config corrections",
"verified references",
"experience files",
"bundles"
],
"raw_extractions_are_immutable": true, "raw_extractions_are_immutable": true,
"historical_outputs_are_never_sources": true "historical_outputs_are_never_sources": true
}, },
@@ -19,8 +25,18 @@
"swiss_work_authorization": "Authorized to work in Switzerland; no visa or employer sponsorship required", "swiss_work_authorization": "Authorized to work in Switzerland; no visa or employer sponsorship required",
"work_authorization_source": "User-confirmed 2026-07-27", "work_authorization_source": "User-confirmed 2026-07-27",
"resume_usage": "Work authorization is optional in the header; mention the B permit or no-sponsorship status when it resolves recruiter uncertainty or the application asks for it", "resume_usage": "Work authorization is optional in the header; mention the B permit or no-sponsorship status when it resolves recruiter uncertainty or the application asks for it",
"languages": {"German": "native", "English": "fluent", "Norwegian": "basic", "Russian": "basic"}, "languages": {
"forbidden_personal_data": ["date of birth", "marital status", "gender", "children"] "German": "native",
"English": "fluent",
"Norwegian": "basic",
"Russian": "basic"
},
"forbidden_personal_data": [
"date of birth",
"marital status",
"gender",
"children"
]
}, },
"education": [ "education": [
{ {
@@ -60,8 +76,16 @@
"start": "2023-10", "start": "2023-10",
"end": "present", "end": "present",
"title_history": [ "title_history": [
{"title": "Senior Data, Analytics & AI Engineer", "start": "2023-10", "end": "2025-04"}, {
{"title": "Staff Data, Analytics & AI Engineer", "start": "2025-04", "end": "present"} "title": "Senior Data, Analytics & AI Engineer",
"start": "2023-10",
"end": "2025-04"
},
{
"title": "Staff Data, Analytics & AI Engineer",
"start": "2025-04",
"end": "present"
}
] ]
}, },
{ {
@@ -69,9 +93,15 @@
"employer": "Robert Bosch Semiconductor Manufacturing Dresden GmbH", "employer": "Robert Bosch Semiconductor Manufacturing Dresden GmbH",
"location": "Dresden, Germany", "location": "Dresden, Germany",
"official_title": "Engineer / Senior Engineer, Data Analysis", "official_title": "Engineer / Senior Engineer, Data Analysis",
"display_title": "Senior Engineer, Data Analysis (Data & ML Engineering)", "display_title": "Senior Data Engineer, Data Analysis",
"display_title_note": "experience_bosch.md sanctions title flexibility for this role: '(Senior) Data Engineer' or '(Senior) Data Analysis Engineer' depending on the JD. 'Senior Data Engineer, Data Analysis' is the user's own preferred wording, confirmed 2026-08-27. official_title stays the formal combined string on the Zeugnis.",
"start": "2020-02", "start": "2020-02",
"end": "2022-12" "end": "2022-12",
"title_history": [
{"title": "Data Engineer, Data Analysis", "start": "2020-02", "end": "2021-01"},
{"title": "Senior Data Engineer, Data Analysis", "start": "2021-01", "end": "2022-12"}
],
"title_history_source": "LinkedIn-confirmed, recorded in experience_bosch.md; user-confirmed 2026-08-27 while reviewing the RUAG C5I resume. Added because claims.json previously carried only the combined official_title with no promotion date, which made a Swisscom-style 'Beforderung <date>' line unwritable from the canonical file alone."
}, },
{ {
"id": "FRAUNHOFER", "id": "FRAUNHOFER",
@@ -106,148 +136,332 @@
"display_title": "Software Engineer", "display_title": "Software Engineer",
"start": "2014-11", "start": "2014-11",
"end": "2015-05" "end": "2015-05"
},
{
"id": "BUNDESWEHR",
"employer": "Bundeswehr (German Armed Forces)",
"location": "Germany",
"display_title": "Officer Candidate / Officer (Second Lieutenant at separation)",
"start": "2008-07",
"end": "2014-11",
"source": "User confirmation 2026-07-10; thiessen_linkedin_profile.md",
"last_verified": "2026-08-27"
} }
], ],
"claims": [ "claims": [
{ {
"id": "SW-1", "id": "SW-1",
"scope": "Primary engineer for pipelines in owned Fulfillment and Product Analysis domains; contributor to the wider company migration.", "scope": "Primary engineer for pipelines in owned Fulfillment and Product Analysis domains; contributor to the wider company migration.",
"allowed_verbs": ["migrated", "implemented", "contributed"], "allowed_verbs": [
"forbidden": ["led the migration of the legacy warehouse", "sole technical lead", "migrated the company warehouse", "owned the full migration"], "migrated",
"implemented",
"contributed"
],
"forbidden": [
"led the migration of the legacy warehouse",
"sole technical lead",
"migrated the company warehouse",
"owned the full migration"
],
"metrics": "unverified" "metrics": "unverified"
}, },
{ {
"id": "SW-2", "id": "SW-2",
"scope": "Component Owner for business-critical Fulfillment ETL pipelines, including operation, data quality, governance, incidents and on-call obligations.", "scope": "Component Owner for business-critical Fulfillment ETL pipelines, including operation, data quality, governance, incidents and on-call obligations.",
"allowed_verbs": ["own", "operate", "maintain", "serve"], "allowed_verbs": [
"own",
"operate",
"maintain",
"serve"
],
"metrics": "unverified" "metrics": "unverified"
}, },
{ {
"id": "SW-3", "id": "SW-3",
"scope": "Build and operate Python data applications on Kubernetes with GitLab CI/CD within the team environment.", "scope": "Build and operate Python data applications on Kubernetes with GitLab CI/CD within the team environment.",
"allowed_verbs": ["build", "deploy", "operate"], "allowed_verbs": [
"build",
"deploy",
"operate"
],
"metrics": "unverified" "metrics": "unverified"
}, },
{ {
"id": "SW-4", "id": "SW-4",
"scope": "Deliver data products, dashboards and analyses with internal B2B stakeholders and product owners; not external consulting or strategic-account delivery.", "scope": "Deliver data products, dashboards and analyses with internal B2B stakeholders and product owners; not external consulting or strategic-account delivery.",
"allowed_verbs": ["deliver", "translate", "partner", "support"], "allowed_verbs": [
"forbidden": ["customer-embedded delivery", "strategic customer delivery", "C-suite advisor"], "deliver",
"translate",
"partner",
"support"
],
"forbidden": [
"customer-embedded delivery",
"strategic customer delivery",
"C-suite advisor"
],
"metrics": "unverified" "metrics": "unverified"
}, },
{ {
"id": "SW-5", "id": "SW-5",
"scope": "Mandatory rotating team Security Champion role for 2025/2026 only; not an award, certification or multi-year distinction.", "scope": "Mandatory rotating team Security Champion role for 2025/2026 only; not an award, certification or multi-year distinction.",
"allowed_verbs": ["serve"], "allowed_verbs": [
"forbidden": ["3 consecutive years", "2023-2026", "Security Champion x3", "owning DevSecOps compliance"], "serve"
],
"forbidden": [
"3 consecutive years",
"2023-2026",
"Security Champion x3",
"owning DevSecOps compliance"
],
"metrics": "100 hours of training and an assessment are source-backed; use only when relevant" "metrics": "100 hours of training and an assessment are source-backed; use only when relevant"
}, },
{ {
"id": "SW-6", "id": "SW-6",
"scope": "Hands-on PySpark use at Swisscom; scale and performance metrics are not verified.", "scope": "Hands-on PySpark use at Swisscom; scale and performance metrics are not verified.",
"allowed_verbs": ["use", "develop", "process"], "allowed_verbs": [
"use",
"develop",
"process"
],
"metrics": "unverified" "metrics": "unverified"
}, },
{ {
"id": "SW-7", "id": "SW-7",
"scope": "Build governed data products and onboard sources within Swisscom's company-wide Data Mesh; never claim ownership or construction of the shared mesh/platform. Atlassian Compass is the metadata/catalogue platform used for data-product metadata and lineage (user-confirmed 2026-07-29); Dennis uses it as a practitioner and does not administer or own the tooling.", "scope": "Build governed data products and onboard sources within Swisscom's company-wide Data Mesh; never claim ownership or construction of the shared mesh/platform. Atlassian Compass is the metadata/catalogue platform used for data-product metadata and lineage (user-confirmed 2026-07-29); Dennis uses it as a practitioner and does not administer or own the tooling.",
"allowed_verbs": ["build", "model", "onboard", "contribute", "document", "maintain"], "allowed_verbs": [
"forbidden": ["built a Data Mesh", "built the Data Mesh", "built AWS Data Mesh", "own the AWS data platform", "own the data platform", "own Atlassian Compass", "administered Compass", "rolled out Compass"], "build",
"model",
"onboard",
"contribute",
"document",
"maintain"
],
"forbidden": [
"built a Data Mesh",
"built the Data Mesh",
"built AWS Data Mesh",
"own the AWS data platform",
"own the data platform",
"own Atlassian Compass",
"administered Compass",
"rolled out Compass"
],
"metrics": "unverified" "metrics": "unverified"
}, },
{ {
"id": "SW-8", "id": "SW-8",
"scope": "Configured domain-grounded LLM assistants in a Swisscom-owned web interface by selecting available models and supplying curated knowledge. Separate exposure includes LiteLLM API use, custom GPTs, Copilot and Kiro.", "scope": "Configured domain-grounded LLM assistants in a Swisscom-owned web interface by selecting available models and supplying curated knowledge. Separate exposure includes LiteLLM API use, custom GPTs, Copilot and Kiro.",
"allowed_verbs": ["configured", "used", "integrated"], "allowed_verbs": [
"forbidden": ["built production LLM systems", "deployed LLM systems", "built LangChain", "agent orchestration", "formal LLM evaluation", "fine-tuned models"], "configured",
"used",
"integrated"
],
"forbidden": [
"built production LLM systems",
"deployed LLM systems",
"built LangChain",
"agent orchestration",
"formal LLM evaluation",
"fine-tuned models"
],
"metrics": "unverified" "metrics": "unverified"
}, },
{ {
"id": "BS-1", "id": "BS-1",
"scope": "Designed and executed integration of containerized ML inference into a 24/7 semiconductor production environment; model-development ownership is not established.", "scope": "Designed and executed integration of containerized ML inference into a 24/7 semiconductor production environment; model-development ownership is not established. Toolchain includes Docker, Kubernetes and Ansible - Ansible use at Bosch was intensive (user-confirmed 2026-08-27) and extended to configuration management and infrastructure automation beyond this single integration, making it standalone Infrastructure-as-Code evidence.",
"allowed_verbs": ["integrated", "containerized", "deployed", "orchestrated"], "allowed_verbs": [
"forbidden": ["trained the image classification model", "owned the full ML lifecycle"], "integrated",
"containerized",
"deployed",
"orchestrated"
],
"forbidden": [
"trained the image classification model",
"owned the full ML lifecycle"
],
"metrics": "qualitative reduction in manual classification is source-backed; exact amount unverified" "metrics": "qualitative reduction in manual classification is source-backed; exact amount unverified"
}, },
{ {
"id": "BS-2", "id": "BS-2",
"scope": "Developed data services in Python, Java and C# over Oracle and Hadoop/Impala for internal analysis teams. Data types worked on (user-confirmed 2026-08-02): semiconductor fab sensor and process data -- defect management records, wafer inspection images, and electrical parameters from Process Control Monitoring (PCM). Relevant as genuine industrial sensor/asset-data experience.", "scope": "Developed data services in Python, Java and C# over Oracle and Hadoop/Impala for internal analysis teams. Data types worked on (user-confirmed 2026-08-02): semiconductor fab sensor and process data -- defect management records, wafer inspection images, and electrical parameters from Process Control Monitoring (PCM). Relevant as genuine industrial sensor/asset-data experience.",
"allowed_verbs": ["developed", "built"], "allowed_verbs": [
"developed",
"built"
],
"metrics": "unverified" "metrics": "unverified"
}, },
{ {
"id": "BS-3", "id": "BS-3",
"scope": "Confirmed Application Owner responsibilities for analytics applications and upstream pipelines, including SLOs, vendors, training and documentation.", "scope": "Confirmed Application Owner responsibilities for analytics applications and upstream pipelines, including SLOs, vendors, training and documentation.",
"allowed_verbs": ["served", "owned", "managed", "defined"], "allowed_verbs": [
"served",
"owned",
"managed",
"defined"
],
"metrics": "unverified" "metrics": "unverified"
}, },
{ {
"id": "BS-4", "id": "BS-4",
"scope": "Built an ELK/Kafka anomaly-detection proof of concept and monitoring; not a company-wide observability platform.", "scope": "Built an ELK/Kafka anomaly-detection proof of concept and monitoring; not a company-wide observability platform.",
"allowed_verbs": ["built", "implemented", "validated"], "allowed_verbs": [
"forbidden": ["built the observability platform", "enterprise observability platform"], "built",
"implemented",
"validated"
],
"forbidden": [
"built the observability platform",
"enterprise observability platform"
],
"metrics": "unverified" "metrics": "unverified"
}, },
{ {
"id": "BS-5", "id": "BS-5",
"scope": "Co-owned the TIBCO Spotfire environment, built C# extensions and co-presented at TIBCO Analytics Forum 2022.", "scope": "Co-owned the TIBCO Spotfire environment, built C# extensions and co-presented at TIBCO Analytics Forum 2022.",
"allowed_verbs": ["co-owned", "built", "co-presented"], "allowed_verbs": [
"co-owned",
"built",
"co-presented"
],
"metrics": "unverified" "metrics": "unverified"
}, },
{
"id": "BS-6",
"scope": "Administered and automated the Linux server estate underpinning fab analytics and ML workloads at Bosch (2020-2022): ML platform hosts, Docker hosts, backend services and the Ansible control path. Developed Ansible extensions, including a credential plugin that retrieved secrets from a password keystore and cached them locally to cut lookup volume and improve scalability and performance. Playbooks were version-controlled in Git and executed push-style from Jenkins/GitLab pipelines. User-confirmed 2026-08-27.",
"allowed_verbs": [
"administered",
"automated",
"developed",
"extended",
"operated",
"built"
],
"forbidden": [
"owned the fab's infrastructure",
"ran the datacenter",
"SRE role or title",
"GitOps",
"any server-count, uptime, SLA or scale figure - none is verified"
],
"metrics": "none verified; the credential-caching plugin reduced keystore lookups, amount unquantified"
},
{ {
"id": "FC-1", "id": "FC-1",
"scope": "Set up Jenkins CI/CD and contributed to SCEDAS development and maintenance.", "scope": "Set up Jenkins CI/CD and contributed to SCEDAS development and maintenance.",
"allowed_verbs": ["set up", "developed", "maintained"], "allowed_verbs": [
"set up",
"developed",
"maintained"
],
"metrics": "unverified" "metrics": "unverified"
}, },
{ {
"id": "FC-2", "id": "FC-2",
"scope": "Contributed ML/NLP components to ARTUS; no publication or model-training ownership.", "scope": "Contributed ML/NLP components to ARTUS; no publication or model-training ownership.",
"allowed_verbs": ["contributed", "implemented", "supported"], "allowed_verbs": [
"forbidden": ["led ARTUS", "trained the speech model"], "contributed",
"implemented",
"supported"
],
"forbidden": [
"led ARTUS",
"trained the speech model"
],
"metrics": "unverified" "metrics": "unverified"
}, },
{ {
"id": "FC-3", "id": "FC-3",
"scope": "Developed containerized microservices for the MISSION research platform.", "scope": "Developed containerized microservices for the MISSION research platform.",
"allowed_verbs": ["developed", "built"], "allowed_verbs": [
"developed",
"built"
],
"metrics": "unverified" "metrics": "unverified"
}, },
{ {
"id": "VZ-1", "id": "VZ-1",
"scope": "Contributed Python and C++ engineering to a distributed video-transcoding backend. Named broadcasters are product context, not direct delivery claims.", "scope": "Contributed Python and C++ engineering to a distributed video-transcoding backend. Named broadcasters are product context, not direct delivery claims.",
"allowed_verbs": ["developed", "engineered", "contributed"], "allowed_verbs": [
"forbidden": ["for CNN, BBC and Al Jazeera", "delivered to CNN", "customer-embedded"], "developed",
"engineered",
"contributed"
],
"forbidden": [
"for CNN, BBC and Al Jazeera",
"delivered to CNN",
"customer-embedded"
],
"metrics": "unverified" "metrics": "unverified"
}, },
{ {
"id": "VZ-2", "id": "VZ-2",
"scope": "Developed automated audio/video integration tests and connected quality gates to CI/CD.", "scope": "Developed automated audio/video integration tests and connected quality gates to CI/CD.",
"allowed_verbs": ["developed", "automated", "integrated"], "allowed_verbs": [
"developed",
"automated",
"integrated"
],
"metrics": "unverified" "metrics": "unverified"
}, },
{ {
"id": "GN-1", "id": "GN-1",
"scope": "Introduced BDD through a proof of concept and held technical responsibility for test automation, training and Jenkins jobs.", "scope": "Introduced BDD through a proof of concept and held technical responsibility for test automation, training and Jenkins jobs.",
"allowed_verbs": ["introduced", "owned", "trained", "administered"], "allowed_verbs": [
"introduced",
"owned",
"trained",
"administered"
],
"metrics": "unverified" "metrics": "unverified"
}, },
{ {
"id": "GN-2", "id": "GN-2",
"scope": "Developed UIPath RPA proofs of concept and acted as an internal contact.", "scope": "Developed UIPath RPA proofs of concept and acted as an internal contact.",
"allowed_verbs": ["developed", "served"], "allowed_verbs": [
"developed",
"served"
],
"metrics": "unverified" "metrics": "unverified"
}, },
{ {
"id": "GN-3", "id": "GN-3",
"scope": "Developed Java/J2EE workflow application features and contributed to integration proofs of concept.", "scope": "Developed Java/J2EE workflow application features and contributed to integration proofs of concept.",
"allowed_verbs": ["developed", "contributed", "migrated"], "allowed_verbs": [
"developed",
"contributed",
"migrated"
],
"metrics": "unverified" "metrics": "unverified"
}, },
{
"id": "BW-1",
"scope": "Completed officer candidate training and officer school during six years of service in the German Armed Forces (Bundeswehr), leaving service as Second Lieutenant. This establishes military and organisational context only; no technical military role, command scope, deployment, NATO service or clearance is established.",
"ownership": "Individual service and completed training.",
"allowed_verbs": [
"completed",
"served",
"left service"
],
"forbidden": [
"current or former security clearance",
"NATO service",
"combat role or deployment",
"technical AI, ICT or cyber work for the military",
"command responsibility or leadership outcomes not explicitly verified"
],
"metrics": "Six years of service and separation as Second Lieutenant are verified; no performance or command-scope metric is established.",
"source": "User confirmation 2026-07-10; thiessen_linkedin_profile.md",
"last_verified": "2026-08-27"
},
{ {
"id": "PP-1", "id": "PP-1",
"scope": "PERSONAL PROJECT (user-supplied 2026-08-25), not professional work. A self-hosted, single-user investing/signal platform Dennis built for himself: ingests daily US-equity prices, fundamentals and sentiment (LLM-assisted); runs one long-only cross-sectional momentum book (top-quintile residual 12-1 momentum, ATR stop/trail, max 15 concurrent names) through scheduled scan and backtest pipelines; surfaces gated setups in a web dashboard plus Telegram alerts. Legitimate use: evidence of self-directed trading-domain fluency and of an end-to-end ingestion/backtest/alerting build outside work. Full-ownership verbs ARE correct here -- unlike his employer work, this is genuinely solo.", "scope": "PERSONAL PROJECT (user-supplied 2026-08-25), not professional work. A self-hosted, single-user investing/signal platform Dennis built for himself: ingests daily US-equity prices, fundamentals and sentiment (LLM-assisted); runs one long-only cross-sectional momentum book (top-quintile residual 12-1 momentum, ATR stop/trail, max 15 concurrent names) through scheduled scan and backtest pipelines; surfaces gated setups in a web dashboard plus Telegram alerts. Legitimate use: evidence of self-directed trading-domain fluency and of an end-to-end ingestion/backtest/alerting build outside work. Full-ownership verbs ARE correct here -- unlike his employer work, this is genuinely solo.",
"allowed_verbs": ["built", "developed", "designed"], "allowed_verbs": [
"built",
"developed",
"designed"
],
"forbidden": [ "forbidden": [
"any trading track record, PnL, return, Sharpe or backtest performance figure -- none is verified and none may ever be quoted", "any trading track record, PnL, return, Sharpe or backtest performance figure -- none is verified and none may ever be quoted",
"calling it distributed, scalable, production or multi-user -- it is single-user and self-hosted", "calling it distributed, scalable, production or multi-user -- it is single-user and self-hosted",
@@ -259,50 +473,230 @@
{ {
"id": "PP-2", "id": "PP-2",
"scope": "Udacity 'AI for Trading' Nanodegree, completed self-study (user-supplied 2026-08-25). Covers quantitative trading fundamentals -- factor construction, alpha signals, backtesting. Pairs with PP-1 as the formal half of self-directed domain grounding.", "scope": "Udacity 'AI for Trading' Nanodegree, completed self-study (user-supplied 2026-08-25). Covers quantitative trading fundamentals -- factor construction, alpha signals, backtesting. Pairs with PP-1 as the formal half of self-directed domain grounding.",
"allowed_verbs": ["completed"], "allowed_verbs": [
"completed"
],
"forbidden": [ "forbidden": [
"listing it as an academic degree, professional certification or quant credential", "listing it as an academic degree, professional certification or quant credential",
"presenting it as equivalent to quantitative research or trading experience", "presenting it as equivalent to quantitative research or trading experience",
"using it to qualify for quant, trader, researcher or portfolio-management roles" "using it to qualify for quant, trader, researcher or portfolio-management roles"
], ],
"metrics": "unverified" "metrics": "unverified"
},
{
"id": "PP-3",
"scope": "PERSONAL PROJECT (user-supplied 2026-08-27), not employer work. A self-hosted Debian server Dennis has operated for ~10 years and administers and hardens himself, running nginx, a mail server, Nextcloud, a VPN server, Docker services and Bitwarden. This is the primary evidence for hands-on Linux administration, system hardening and security configuration, and it is current and continuous - unlike the Bosch Linux work, which ended in 2022. User states he genuinely enjoys this kind of work, including physical infrastructure.",
"allowed_verbs": [
"operate",
"administer",
"harden",
"run",
"maintain",
"self-host"
],
"forbidden": [
"calling it enterprise, production, multi-user or business-critical infrastructure",
"implying professional SRE, sysadmin or hosting employment",
"any uptime, availability, SLA, user-count or scale figure - none is verified",
"presenting it as employer work or omitting that it is self-hosted and personal",
"using it as evidence of datacenter or physical-infrastructure experience"
],
"metrics": "none; ~10 years of continuous operation is the only quantity, and it is self-reported"
} }
], ],
"skills": [ "skills": [
{"name": "Python", "evidence": "production-current", "output": "allowed"}, {
{"name": "SQL", "evidence": "production-current", "output": "allowed"}, "name": "Python",
{"name": "PySpark", "evidence": "production-current", "output": "allowed"}, "evidence": "production-current",
{"name": "Kafka", "evidence": "production-current", "output": "allowed"}, "output": "allowed"
{"name": "Airflow", "evidence": "production-current", "output": "allowed"}, },
{"name": "AWS", "evidence": "production-current", "output": "allowed"}, {
{"name": "CloudFormation", "evidence": "production-current", "output": "allowed"}, "name": "SQL",
{"name": "Atlassian Compass", "evidence": "production-current", "output": "allowed", "note": "Metadata/catalogue platform for data-product metadata and lineage at Swisscom (user-confirmed 2026-07-29). Practitioner use only — do not claim administration, rollout or ownership. Satisfies 'or similar metadata/catalogue platform' phrasing; is NOT a substitute claim for Purview, Collibra or Alation, which remain unevidenced."}, "evidence": "production-current",
{"name": "Kubernetes", "evidence": "production-current-and-historical", "output": "allowed"}, "output": "allowed"
{"name": "Docker", "evidence": "production-current-and-historical", "output": "allowed"}, },
{"name": "Java", "evidence": "production-historical", "output": "allowed-with-context"}, {
{"name": "C#", "evidence": "production-historical", "output": "allowed-with-context"}, "name": "PySpark",
{"name": "C++", "evidence": "production-historical-limited", "output": "allowed-with-context"}, "evidence": "production-current",
{"name": "JavaScript", "evidence": "production-historical-limited", "output": "allowed-with-context"}, "output": "allowed"
{"name": "LiteLLM", "evidence": "hands-on-current", "output": "allowed-with-context"}, },
{"name": "custom GPTs", "evidence": "hands-on-current", "output": "allowed-with-context"}, {
{"name": "Kiro", "evidence": "hands-on-current", "output": "allowed-with-context"}, "name": "Kafka",
{"name": "Copilot", "evidence": "hands-on-current", "output": "allowed-with-context"}, "evidence": "production-current",
{"name": "quantitative/systematic trading concepts", "evidence": "coursework-and-personal-project", "output": "allowed-with-context", "note": "Udacity AI for Trading nanodegree (PP-2) plus the self-built momentum platform (PP-1): factor construction, cross-sectional/residual momentum, ATR stops, backtesting. Self-directed only — NO professional quant, trading or finance experience. Never list under a Professional Experience skills line without the personal-project context, and never as a quant qualification."}, "output": "allowed"
{"name": "backtesting", "evidence": "personal-project", "output": "allowed-with-context", "note": "PP-1 scheduled backtest pipelines, personal scale. Never quote a result or performance figure."}, },
{"name": "TensorFlow/Keras", "evidence": "certification", "output": "certification-context-only"}, {
{"name": "PyTorch", "evidence": "coursework-or-personal-unverified", "output": "certification-context-only"}, "name": "Airflow",
{"name": "TypeScript", "evidence": "unverified", "output": "forbidden"}, "evidence": "production-current",
{"name": "FastAPI", "evidence": "unverified", "output": "forbidden"}, "output": "allowed"
{"name": "Flask", "evidence": "unverified", "output": "forbidden"}, },
{"name": "Django", "evidence": "unverified", "output": "forbidden"}, {
{"name": "LangChain", "evidence": "never-used", "output": "forbidden"}, "name": "AWS",
{"name": "LangGraph", "evidence": "never-used", "output": "forbidden"}, "evidence": "production-current",
{"name": "LlamaIndex", "evidence": "never-used", "output": "forbidden"}, "output": "allowed"
{"name": "formal model evaluation", "evidence": "unverified", "output": "forbidden"}, },
{"name": "LLM fine-tuning", "evidence": "unverified", "output": "forbidden"}, {
{"name": "Azure", "evidence": "unverified", "output": "forbidden"}, "name": "CloudFormation",
{"name": "GCP", "evidence": "unverified", "output": "forbidden"}, "evidence": "production-current",
{"name": "Terraform", "evidence": "unverified", "output": "forbidden"} "output": "allowed"
},
{
"name": "Atlassian Compass",
"evidence": "production-current",
"output": "allowed",
"note": "Metadata/catalogue platform for data-product metadata and lineage at Swisscom (user-confirmed 2026-07-29). Practitioner use only — do not claim administration, rollout or ownership. Satisfies 'or similar metadata/catalogue platform' phrasing; is NOT a substitute claim for Purview, Collibra or Alation, which remain unevidenced."
},
{
"name": "Kubernetes",
"evidence": "production-current-and-historical",
"output": "allowed"
},
{
"name": "Ansible",
"evidence": "production-historical",
"output": "allowed",
"note": "User-confirmed 2026-08-27: worked intensively with Ansible at Bosch (2020-2022) for configuration management and infrastructure automation, including the BS-1 ML-inference orchestration. Was absent from claims.json despite already appearing in experience_bosch.md BS-1 bullet variants. Counts as genuine Infrastructure-as-Code evidence alongside CloudFormation. Does NOT by itself license claiming Terraform (still unverified) or GitOps as a named practice (see gitops_pending)."
},
{
"name": "Linux administration",
"evidence": "production-historical-and-personal-current",
"output": "allowed",
"note": "User-confirmed 2026-08-27 and previously ABSENT from claims.json entirely. Professional: at Bosch (2020-2022) Linux servers carried everything - ML platform, Docker hosts, backend services, Ansible control - and he administered and automated them (see BS-6). Personal and current: a self-hosted Debian server he has run and hardened for ~10 years (see PP-3). Hardening and security configuration evidence leans on the personal side; say so rather than implying an employer mandate. Does NOT license claiming datacenter/physical infrastructure work, which remains a genuine gap."
},
{
"name": "Docker",
"evidence": "production-current-and-historical",
"output": "allowed"
},
{
"name": "Java",
"evidence": "production-historical",
"output": "allowed-with-context"
},
{
"name": "C#",
"evidence": "production-historical",
"output": "allowed-with-context"
},
{
"name": "C++",
"evidence": "production-historical-limited",
"output": "allowed-with-context"
},
{
"name": "JavaScript",
"evidence": "production-historical-limited",
"output": "allowed-with-context"
},
{
"name": "LiteLLM",
"evidence": "hands-on-current",
"output": "allowed-with-context"
},
{
"name": "custom GPTs",
"evidence": "hands-on-current",
"output": "allowed-with-context"
},
{
"name": "Kiro",
"evidence": "hands-on-current",
"output": "allowed-with-context"
},
{
"name": "Copilot",
"evidence": "hands-on-current",
"output": "allowed-with-context"
},
{
"name": "quantitative/systematic trading concepts",
"evidence": "coursework-and-personal-project",
"output": "allowed-with-context",
"note": "Udacity AI for Trading nanodegree (PP-2) plus the self-built momentum platform (PP-1): factor construction, cross-sectional/residual momentum, ATR stops, backtesting. Self-directed only — NO professional quant, trading or finance experience. Never list under a Professional Experience skills line without the personal-project context, and never as a quant qualification."
},
{
"name": "backtesting",
"evidence": "personal-project",
"output": "allowed-with-context",
"note": "PP-1 scheduled backtest pipelines, personal scale. Never quote a result or performance figure."
},
{
"name": "TensorFlow/Keras",
"evidence": "certification",
"output": "certification-context-only"
},
{
"name": "PyTorch",
"evidence": "certification",
"output": "certification-context-only",
"note": "IBM AI Engineering Professional Certificate (Coursera, 4 Jun 2020) includes the course \"Deep Neural Networks with PyTorch\"; certificate PDF verified 2026-08-27. Same footing as TensorFlow/Keras: certification context only, never presented as production or project experience."
},
{
"name": "TypeScript",
"evidence": "unverified",
"output": "forbidden"
},
{
"name": "FastAPI",
"evidence": "unverified",
"output": "forbidden"
},
{
"name": "Flask",
"evidence": "unverified",
"output": "forbidden"
},
{
"name": "Django",
"evidence": "unverified",
"output": "forbidden"
},
{
"name": "LangChain",
"evidence": "never-used",
"output": "forbidden"
},
{
"name": "LangGraph",
"evidence": "never-used",
"output": "forbidden"
},
{
"name": "LlamaIndex",
"evidence": "never-used",
"output": "forbidden"
},
{
"name": "formal model evaluation",
"evidence": "unverified",
"output": "forbidden"
},
{
"name": "LLM fine-tuning",
"evidence": "unverified",
"output": "forbidden"
},
{
"name": "Azure",
"evidence": "unverified",
"output": "forbidden"
},
{
"name": "GCP",
"evidence": "unverified",
"output": "forbidden"
},
{
"name": "Terraform",
"evidence": "unverified",
"output": "forbidden"
},
{
"name": "GitOps",
"evidence": "pending-user-clarification",
"output": "forbidden",
"note": "RESOLVED 2026-08-27, and the answer is NO. User confirmed: Ansible playbooks lived in Git, but execution was PUSH-based out of Jenkins/GitLab pipelines - there was no pull-based reconciliation agent (Argo CD, Flux). That is version-controlled, CI-driven infrastructure automation, not GitOps. The word stays forbidden in every document. The SUBSTANCE is writable and should be written: 'versionskontrollierte Infrastrukturautomatisierung mit Ansible aus Git, ausgefuehrt ueber Jenkins-/GitLab-Pipelines'. The Kdo Cy JD names 'Pull-GitOps' explicitly, so precision here is an asset, not a loss."
}
], ],
"global_forbidden_output_patterns": [ "global_forbidden_output_patterns": [
"petabyte scale", "petabyte scale",
@@ -9,14 +9,19 @@
### Achievement BW-1: Officer Training and Service ### Achievement BW-1: Officer Training and Service
**Canonical ID:** BW-1
**Last verified:** 2026-08-27
**User's role:** Officer candidate / officer **User's role:** Officer candidate / officer
**Status:** Completed service; resigned as Second Lieutenant **Status:** Completed service; resigned as Second Lieutenant
**Ownership scope:** Individual service and completed training. No command scope, deployment or technical military responsibility is established.
**Verified result / metric state:** Six years of service and separation as Second Lieutenant are verified; no performance metric is established.
**Context:** Completed officer candidate training and officer school, then served in the German Armed Forces for six years. **Context:** Completed officer candidate training and officer school, then served in the German Armed Forces for six years.
**Safe bullet direction:** Completed officer candidate training and officer school during six years in the German Armed Forces (Bundeswehr), leaving service as Second Lieutenant. Do not imply a current clearance, NATO service, combat role, technical AI work, or responsibilities not verified. **Safe bullet direction:** Completed officer candidate training and officer school during six years in the German Armed Forces (Bundeswehr), leaving service as Second Lieutenant. Do not imply a current clearance, NATO service, combat role, technical AI work, or responsibilities not verified.
**ATS keywords:** German Armed Forces, Bundeswehr, officer, multinational environment, operational context, structured leadership **ATS keywords:** German Armed Forces, Bundeswehr, officer, multinational environment, operational context, structured leadership
**Relevant role context:** Defence, military and public-security employers; organisational familiarity rather than technical evidence.
**Reframing notes:** **Reframing notes:**
- Defence / NATO roles: Include as concise context for operational judgement and organisational familiarity. - Defence / NATO roles: Include as concise context for operational judgement and organisational familiarity.