Software Engineerfocused on building and hardening secure software.
I'm a full-stack engineer with about 5 years of experience. I like building things, then poking at them until they break because that's usually where you find out what assumptions were quietly holding everything together. From there, I rebuild with security, clarity, and correctness in mind.
Underneath it all, I'm just curious about how systems really behave, especially when you push them beyond where they were designed to go.
About
I'm a software engineer who's curious about how software breaks: insecure defaults, flawed assumptions, the small implementation mistakes that end up mattering a lot. And once I find those cracks, I want to actually fix them, not just patch over them.
To me, security is a part of writing good code. Clearer logic, safer interfaces, and a real sense of how both users and attackers actually interact with what you've built. I build systems, pick them apart to find where they're weak, and rebuild with better patterns and honest trade-offs.
Most of my projects start as excuses to learn something. I use them to dig into failure modes, reflect on what I find, and turn abstract security ideas into decisions I can actually defend in real engineering work.
What I Do
Building Software
- Design and implement application features end-to-end
- Work with APIs, data models, and application logic
- Write maintainable, well-documented code
- Debug, refactor, and improve existing systems
Breaking Software
- Explore common vulnerability classes and failure modes
- Reproduce and analyze insecure patterns
- Study how real systems are abused
- Document findings clearly and practically
Rebuilding It Securely
- Refactor toward safer defaults
- Improve authentication, authorization, and data handling
- Add validation, guardrails, and observability
- Capture lessons learned so systems scale safely
Featured Work
Sentri
A security-focused application built to practice secure software design and engineering.
- Security-first architecture decisions
- Authentication, authorization, and input handling
- Logging and auditability
Tech: Python/Django, PostgreSQL
Webhook Gateway
Go service that verifies and forwards webhooks.
- HMAC signature verification
- Replay protection
- Rate limiting per provider
- Structured logging with request IDs
Tech: Go
AppSec Learning Lab
OWASP Juice Shop
Hands-on exploration of common application security vulnerabilities using OWASP Juice Shop.
- Identifying OWASP Top 10 issues
- Understanding real-world impact
- Documenting mitigations and fixes
Education & Certifications
- BEng in Electrical and Electronics Engineering
- Full Stack Web Development and Computer Science — BloomTech (formerly Lambda School)
- CompTIA Security+
- Master of Cybersecurity & Threat Intelligence, MCTI (Starting 2027)
Links
Email: sandra_philips@outlook.com
GitHub: github.com/Sandravaphilips
LinkedIn: linkedin.com/in/sandravaphilips
Podcast: youtube.com/@OffTheTerminal