← ALL SPEAKERS
Brian Sletten
SPEAKER 8 SESSIONS

BrianSletten

FORWARD LEANING SOFTWARE ENGINEER @ BOSATSU CONSULTING
01 / BIOGRAPHY

Brian Sletten is a liberal arts-educated software engineer with a focus on forward-leaning technologies. His experience has spanned many industries including retail, banking, online games, defense, finance, hospitality and health care. He has a B.S. in Computer Science from the College of William and Mary and lives in Auburn, CA. He focuses on web architecture, resource-oriented computing, social networking, the Semantic Web, AI/ML, data science, 3D graphics, visualization, scalable systems, security consulting and other technologies of the late 20th and early 21st Centuries. He is also a rabid reader, devoted foodie and has excellent taste in music. If pressed, he might tell you about his International Pop Recording career.

02 / PRESENTATIONS AT ARCHCONF'26
Mon Dec 7 · 9:00 AM
Securing the Agentic Frontier : Architecture, Risk, and Practice

While people are fixating on the threat AI brings to cybersecurity as a discipline, there’s the considerably more pedestrian but crucial perspective of securing these systems. The role of the CISO is expanding beyond security practices to include risk management, compliance, and more and these role expansions will cascade through the organization. Agentic systems collapse traditional boundaries between user, system, and adversary. Not only do they introduce new risks, they challenge foundational assumptions in security engineering. Identity and authorization grants are fluid based upon contextual composition, behavior becomes non-deterministic, and threat models become continuous, not static. What are the risks, challenges, and opportunities that are unleashed at the intersection of security postures, agents with agency, ambient authority, context-specific interactions, and engineering discipline? How does one grow this capability in an organization and how does one align their career in this direction.

Tue Dec 8 · 8:30 AM STATICANALYSIS
Automating Security Fixes with OpenRewrite

Security problems empirically fall into two categories: bugs and flaws. Roughly half of the problems we encounter in the wild are bugs and about half are design flaws. A significant number of the bugs can be found through automated testing tools which frees you up to focus on the more pernicious design issues. Even in the time of AI, there's a discussion to be had.  In addition to detecting the presence of common bugs as we have done with static analysis for years, however, we can also imagine automating the application of corrective refactoring. In this talk, I will discuss using OpenRewrite and the Moderne cli to fix common security issues and keep them from coming back.  

Tue Dec 8 · 10:30 AM STATICANALYSIS
Automating Security Fixes with OpenRewrite

Security problems empirically fall into two categories: bugs and flaws. Roughly half of the problems we encounter in the wild are bugs and about half are design flaws. A significant number of the bugs can be found through automated testing tools which frees you up to focus on the more pernicious design issues. Even in the time of AI, there's a discussion to be had.  In addition to detecting the presence of common bugs as we have done with static analysis for years, however, we can also imagine automating the application of corrective refactoring. In this talk, I will discuss using OpenRewrite and the Moderne cli to fix common security issues and keep them from coming back.  

Tue Dec 8 · 5:00 PM
Resource-Oriented Architecture Patterns

The typical technologist has a fairly straightforward perspective about the use of resources in modern software systems. They understand the concept of stable identifiers and what some of the HTTP verbs are intended for based upon experiences with the Web.

Tue Dec 8 · 1:00 PM
The Evolution of RAG Context

Retrieval Augmented Generation (RAG) systems have emerged to provide guardrails to spirited non-determinism of unfettered Large Language Models. While useful, they are clearly not enough even in the more advanced configurations of query rewriting, domain/chunk-size alignment, and re-ranking activities. At the edge of energetic AI wave is a new form of token generation involving concepts and actions that will take things even further.

Tue Dec 8 · 3:00 PM
The Evolution of RAG Context

Retrieval Augmented Generation (RAG) systems have emerged to provide guardrails to spirited non-determinism of unfettered Large Language Models. While useful, they are clearly not enough even in the more advanced configurations of query rewriting, domain/chunk-size alignment, and re-ranking activities. At the edge of energetic AI wave is a new form of token generation involving concepts and actions that will take things even further.

Wed Dec 9 · 1:30 PM DESIGN
Web Security for APIs

There's a clear need for security in the software systems that we build. The problem for most organizations is that they don't want to spend any money on it. Even if they did, they often have no idea how much to spend. No particular initiative is likely to imbue your system with "security", but a strong, deep defensive approach is likely to give you a fighting chance of getting it right. Web Security as applied to APIs in particular are an important part of the plan. In this workshop, we'll show you how approaches to defining "enough" as well as concrete techniques to employ incrementally in your designs. In this workshop, we will pick a hands on framework for implementation, but the ideas will generally be standards-based and transcend technology choice so you should have a strategy for mapping the ideas into your own systems.

Wed Dec 9 · 3:15 PM DESIGN
Web Security for APIs

There's a clear need for security in the software systems that we build. The problem for most organizations is that they don't want to spend any money on it. Even if they did, they often have no idea how much to spend. No particular initiative is likely to imbue your system with "security", but a strong, deep defensive approach is likely to give you a fighting chance of getting it right. Web Security as applied to APIs in particular are an important part of the plan. In this workshop, we'll show you how approaches to defining "enough" as well as concrete techniques to employ incrementally in your designs. In this workshop, we will pick a hands on framework for implementation, but the ideas will generally be standards-based and transcend technology choice so you should have a strategy for mapping the ideas into your own systems.

All signal.
Zero fluff.
DECEMBER 7 - 10, 2026 · OPAL SANDS RESORT · CLEARWATER, FL