Skip to content
View sandrif's full-sized avatar

Block or report sandrif

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
sandrif/README.md

About

** Software Engineer | Senior Quality Assurance Engineer | API & Integration Security | Enterprise Integrations**

Software engineering, enterprise integrations, and quality.

Currently investing in a structured engineering curriculum: deepening backend architecture (Java · Spring Boot), full-stack patterns (TypeScript · React), and production — cloud, observability, system design.

Increasingly interested in the security dimension — integration attack surfaces, and resilient system design.

Hobby projects:

  • Web design studio - HTML, CSS, JavaScript, React
  • Learning Kali tools

Core expertise

  • Backend — Node.js · Express.js · REST APIs · Microservices · MongoDB · PostgreSQL
  • Frontend — React · TypeScript · HTML/CSS
  • Languages — JavaScript · TypeScript · Java · SQL · Groovy · Python
  • Integrations — SAP Cloud Integration Suite · iPaaS · ADP · NetSuite · Xero · Sage Intact · QuickBooks
  • Quality — QA strategy · API & integration testing · Automation frameworks (Selenium WebDriver, Cucumber, Playwright)

Engineering curriculum

A project-driven path toward full-stack engineering.

Step Focus Stack
1 REST APIs, auth, testing, CI/CD Java · Spring Boot · PostgreSQL · Docker
2 Full-stack, OAuth2, caching React · TypeScript · Redis · NestJS
3 Data services, async, observability Python · FastAPI · Kafka · Grafana
4 Cloud, IaC, production hardening & security AWS/Azure · Terraform · OpenTelemetry

Projects

  • (Task & Team Management API)
  • (Bookings & Payments App)
  • (Product Analytics Service)

CyberSecurity and Application Security

Web application and integration security alongside engineering work.

  • CompTIA Security+ - In Progress (Exam scheduled: August 2026)
  • ISC2 CSSLP - Exam Candidate (Target: November 2026)
  • PortSwigger Academy — Web Security labs (in progress)
  • eJPT — (plan to take an exam 2027)

Connect

sandrafaltysova@duck.com

Pinned Loading

  1. shopping-list-app shopping-list-app Public

    JavaScript

  2. task-team-api task-team-api Public

    Java

  3. my-garden-hobby-app my-garden-hobby-app Public

    JavaScript

  4. newbie-robot newbie-robot Public

    Python

  5. FlowerPower FlowerPower Public

    Forked from IoT-team1/FlowerPower

    Copy of university team project

    JavaScript 1

  6. MedMan MedMan Public

    Forked from denis-fiser/MedMan

    Copy of university team project: Doctor Appointment Reservation System that simplifies and digitises the process of booking, managing, and tracking medical appointments. The application enables pat…

    JavaScript