resume
Arthur Schneider
Platform engineer · Linux, cloud, security, and AI infrastructure
// summary
Platform engineer with 10 years across Linux, cloud, and security, currently building an enterprise AI agent platform alongside the Linux estate that funds it. At Centene (Fortune 25 healthcare), a core engineer on the platform behind a 28,000-host RHEL estate serving 50+ tenant teams: led the zero-outage Satellite estate upgrade, built its 30-role configuration-as-code layer, drove the engineering of an enterprise PAM migration across 700+ hosts, contributed to the multi-tenant AAP-on-OpenShift migration from planning through cutover, and founded the org-wide AI agent platform: a governed skills marketplace, the accepted enterprise agent standard, hook-enforced runtime guardrails, and an open-source MCP server. Ships platform tooling other engineers adopt and maintain.
// experience
Senior Systems / Platform Engineer · Centene (Fortune 25)
- Core contributor to the multi-tenant migration of Ansible Automation Platform onto OpenShift (ACM, Argo CD GitOps) serving 50+ tenant teams, involved from planning through cutover; co-authored the multi-tenancy ADR (AppProjects, Kyverno, Kubernetes RBAC, NetworkPolicy) that cut tenant onboarding from weeks to days.
- Founded the org-wide AI agent platform: built the governed skills and plugins marketplace (19 skills, 5 plugins, blocking CI validators, self-service team onboarding) adopted as the organization’s single source of truth, and authored the accepted enterprise standard for AI agents touching production systems.
- After an ungoverned AI-assisted script corrupted production data, built the hook-enforced runtime guardrail framework adopted as the enterprise standard; the governed toolchain scored 100% on a 19-assertion internal benchmark vs 32% without it.
- Drove the engineering of the enterprise PAM migration (sudo/SSSD to Delinea Server Suite) across 700+ production hosts and 77 application groups: designed the approach, migrated the privilege configuration to centrally auditable AD-backed roles, and supported every production cutover wave.
- Built the PAM migration toolchain: a preflight rule engine enforcing separation of duties and blocking dangerous privilege wildcards, plus dry-run apply/verify automation with a change-number audit trail. Cut operator effort 70% per wave; now maintained by other engineers.
- Primary engineer for the enterprise Red Hat Satellite platform (master plus six capsules across on-prem, AWS, and Azure with F5 capsule HA); led its zero-outage upgrade across two version hops in a single change window, clearing every outstanding CVE.
- Built the Satellite configuration-as-code platform: 30 Ansible roles replacing UI-driven configuration with version-controlled, peer-reviewed code, and the GitLab CI pipeline that maps each configuration change to the matching automation job.
- De facto maintainer of the enterprise Ansible execution-environment platform serving 11 teams: introduced its first CI/CD, automated testing, and promote/rollback discipline, and delivered images with dependency sets those teams could not build themselves.
- Traced a fleet-wide provisioning outage to the bootloader-to-kernel handoff after systematically disproving 13 candidate causes by direct test; separately found silent configuration drift that had the compliance platform reporting success while enforcing nothing.
- Authored 14 Architecture Decision Records setting platform direction and wrote strategy papers for Director-through-VP audiences; additionally served as Scrum Master, restructuring the team’s portfolio into a charge-code-driven hierarchy.
- Architected the internal documentation portal and RAG chatbot: a CloudFront-fronted docs portal with Bedrock Claude indexed across Markdown, Confluence, GitLab, and ServiceNow KB, with SAML federation enforcing knowledge-tier RBAC.
Senior Cyber Security Engineer · U.S. Department of Veterans Affairs
- Spearheaded a Zero Trust capability assessment using the CISA Zero Trust Maturity Model across Identity, Device, Network, Data, and Application & Workload pillars; delivered the baseline and gap analysis, Security Impact Analysis, and implementation roadmaps.
- Implemented ServiceNow-based tracking and dashboards monitoring Zero Trust progress across systems and teams, eliminating duplicate cross-team efforts.
Cyber Security Engineer · Ford Motor Company
- Led the Trend Micro Deep Security and Vision One migration, consolidating HIPS, AV, firewall, EDR, and XDR from legacy tools into a unified security platform.
- Orchestrated Habitat-to-Ansible re-platforming for configuration and deployment management across system environments.
- Drove the CISA v2 Device-pillar Zero Trust evaluation: inventory management, configuration control, and EDR/XDR rollout aligned with ZT principles.
Linux Systems Engineer · General Dynamics Land Systems
- Managed the Red Hat Satellite implementation for the RHEL fleet: automated patching, repository configuration, and HA/DR with Ansible integration.
- Oversaw the Solaris-to-RHEL migration: scripted automated migration with post-migration validation, minimizing downtime.
Security Operations Specialist · Ford Motor Company
- Administered QRadar SIEM and HX/FireEye XDR operations; built specialized tooling to streamline administration within appliance constraints.
Linux Systems Administrator · General Dynamics Land Systems
- Linux operations across Solaris and RHEL: access management, application and database server deployments, and UNIX team tooling.
// selected projects
obsidian-toolkit (open source)
MCP server, Claude Code skill, and conventions for agent-driven Obsidian knowledge-base workflows. TypeScript, unit-tested, MIT licensed.
Homelab platform (rt-541.io)
Self-hosted platform on a two-node Proxmox cluster: 30+ Docker services behind Traefik with automated TLS, DNS, analytics, and monitoring, all managed as code (Ansible, Terraform, per-host Compose monorepo). Public mirrors: kuat-drive-yards-public, homelab-config-public.
Day-2 Satellite reporting platform
Eight-flavor reporting suite replacing seven legacy shell scripts; each report is simultaneously archived as markdown, emailed to its distribution list, and published to the documentation wiki, backed by pure-stdlib filter plugins and per-flavor Molecule test scenarios.
ChurnCore — Project Zomboid mod suite (in development)
Three-mod suite for a private Build 42 multiplayer server: a framework engine (stages, registries, UI, client/server state sync), an event director driving missions, radio broadcasts, and dynamic events, and a bridge to an NPC mod. Lua, unit-tested, with a scripted deploy loop.
Advent Harvest (in development)
Turn-based creature-team battler with roguelite dungeon crawling, built in Godot 4: seed-driven procedural overworld generation from continents to archipelagos, latitude- and elevation-driven biomes, hex-grid pathfinding, and a tested save system.
// skills
- AWS (EC2, IAM, KMS, Lambda, Bedrock, OpenSearch, STS), OpenShift 4.16–4.20, ACM, Argo CD, Kyverno, vSphere, Proxmox
- Ansible Automation Platform 2.4/2.6, Ansible (collections, roles, Molecule, ansible-lint), Terraform, Packer, Event-Driven Ansible, GitLab CI/CD, Configuration-as-Code
- RHEL 7–10, Amazon Linux 2023, SUSE, Ubuntu, Red Hat Satellite 6.16–6.19, LEAPP, SSSD, Delinea Server Suite / Centrify
- Claude Code (skills, plugins, hooks, subagents), Model Context Protocol (server authoring; open source: obsidian-toolkit), agent evals and benchmarking, runtime guardrails and policy enforcement, AWS Bedrock RAG, AI governance standards
- Python, Bash, PowerShell, TypeScript, Jinja2, YAML
- EDR/XDR (CrowdStrike Falcon, MS Defender, Trend Micro Vision One, HX/FireEye), SIEM (QRadar, Splunk), PAM (Delinea, sudo, SSSD), IAM/MFA (RSA SecurID, AD integration), vulnerability management (Tenable Nessus), hardening (CIS L2, ansible-lockdown), POSIX ACLs, Zero Trust (CISA ZTMM), SOX evidence, enterprise PKI
- Architecture Decision Records (14 authored), Scrum / SAFe, portfolio and backlog governance, ServiceNow change control, technical writing for executive audiences
// certifications
- RHCE (RHEL 7), CompTIA CySA+, CompTIA Security+, CompTIA Network+, CCNA
- RHCE (EX294), Red Hat Certified OpenShift Administrator (EX280), OpenShift Automation (EX380)
// education
Associate degree · Networking Specialist · Jackson College