Uploaded March 2026 | Updated September 2026, 2 weeks ago
Can you take a 6-month security review and crush it down to 2 hours?
Jim Gough (Java Champion and API Architect at Morgan Stanley) reveals how to bridge the "Developer-Security Gap" using Architecture as Code. In this InfoQ video, he introduces CALM (Common Architecture Language Model) - an open-source framework designed to automate compliance, enforce micro-segmentation, and eliminate the "undifferentiated heavy lifting" that plagues senior engineers and architects.
Whether you are managing billions of requests or navigating complex Kubernetes environments, this session provides a roadmap for building secure-by-design systems without sacrificing developer velocity.
⏱️ Video Timestamps (For Navigation)
0:00 – The "Accidental Architect" & API Complexity
2:45 – The Developer-Infrastructure & Security Gaps
5:12 – Threat Modeling: Using STRIDE for API Design
8:30 – Demo: Exploiting a "Secure" Kubernetes Cluster
12:15 – Introducing CALM: Common Architecture Language Model
15:40 – Nodes, Relationships, and Controls as Code
18:55 – Live Demo: From Pattern to Secure Deployment
23:10 – The Roadmap: Drift Detection & AI Integration
26:45 – Q&A: Retrofitting Legacy Systems & OpenAPI Evolution
🔗 Transcript available on InfoQ: bit.ly/4roeNEz
#SoftwareArchitecture #APIManagement #CyberSecurity #PlatformEngineering #Kubernetes #Java
📅 Subscribe for weekly talks from senior engineers at companies like Netflix, Spotify, and IBM.
Can you take a 6-month security review and crush it down to 2 hours?
Jim Gough (Java Champion and API Architect at Morgan Stanley) reveals how to bridge the "Developer-Security Gap" using Architecture as Code. In this InfoQ video, he introduces CALM (Common Architecture Language Model) - an open-source framework designed to automate compliance, enforce micro-segmentation, and eliminate the "undifferentiated heavy lifting" that plagues senior engineers and architects.
Whether you are managing billions of requests or navigating complex Kubernetes environments, this session provides a roadmap for building secure-by-design systems without sacrificing developer velocity.
⏱️ Video Timestamps (For Navigation)
0:00 – The "Accidental Architect" & API Complexity
2:45 – The Developer-Infrastructure & Security Gaps
5:12 – Threat Modeling: Using STRIDE for API Design
8:30 – Demo: Exploiting a "Secure" Kubernetes Cluster
12:15 – Introducing CALM: Common Architecture Language Model
15:40 – Nodes, Relationships, and Controls as Code
18:55 – Live Demo: From Pattern to Secure Deployment
23:10 – The Roadmap: Drift Detection & AI Integration
26:45 – Q&A: Retrofitting Legacy Systems & OpenAPI Evolution
🔗 Transcript available on InfoQ: bit.ly/4roeNEz
#SoftwareArchitecture #APIManagement #CyberSecurity #PlatformEngineering #Kubernetes #Java
📅 Subscribe for weekly talks from senior engineers at companies like Netflix, Spotify, and IBM.










