Skip to content
View FlightSchool-io's full-sized avatar

Block or report FlightSchool-io

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
FlightSchool-io/README.md

🚀 Web Application Security & DevSecOps Project Portfolio

Artifact-as-Legacy | Quantum-Safe Builder | Actionable Mentor
Welcome! I’m Rashard—a Web Application Security Engineer, blueprint architect, and DevSecOps leader. My expertise spans policy-as-code, quantum-safe development, and actionable mentorship. I build resilient cloud-native applications end-to-end and empower engineers with practical, repeatable progress.


🌐 About This Portfolio

This repository is both a technical showcase and a movement-building hub.
It features:

  • Hands-on demonstrations across cloud security, Post-Quantum Cryptography (PQC), and advanced automation.
  • Every commit as a teaching moment—crafted for transparency, repeated for mastery, and designed to inspire.

🛠️ Role Alignment: Skills in Action

This portfolio demonstrates the impact of engineers who secure software supply chains at scale, with a focus on ownership, reproducibility, and mentorship.

Capability Area Demonstrated Skillset
Automated Vulnerability Detection CodeQL queries, Semgrep rules, GHAS alert triage, Copilot Autofix
Secure Dev Lifecycle SOP.md workflows, annotated CI/CD security integration
Tooling & Frameworks GitHub Advanced Security, Codespaces, SBOM generation
Campaign Ownership Security skit modules, onboarding artifacts, enablement
Supply Chain Risk Reduction Secrets scanning, dependency analysis, PQC migration
Mentorship & Enablement Training modules, Cornell-style SOPs, cohort feedback
Cross-Functional Collaboration Playbooks, annotated demos, onboarding systems

💡 Philosophy: Actionable DevSecOps + Secure Design

  • Learn by doing: Iterative projects solving real-world challenges
  • Share what works: Document wins, failures, and refactors
  • Embed security: GitHub Advanced Security, Codespaces, Quantum tooling
  • Build culture: Enablement, cohort feedback, cross-org collaboration

🏆 Featured Competencies

  • AppSec: OWASP Top 10, Threat Modeling, Secure SDLC, Manual/Automated Testing
  • DevSecOps: SAST, SCA, Secret Scanning, GitHub Actions, Supply Chain Hardening
  • Cloud: Kubernetes, IaC Security, Runtime Controls, PQC Readiness
  • Policy: Security Standards, Developer Training, Power BI Governance Reporting

🚧 Live Projects & Demos

  • SQL Injection Incident Response (OWASP Juice Shop)
  • DevSecOps Pipeline w/ Post-Quantum Scanning
  • Supply Chain Security Lab (Secrets, CodeQL, Dependabot)
  • Quantum Security Toolkit (Assessment & Migration Planning)
  • Cloud-Native Patterns (IaC + Runtime Tests)

🎭 Security Skit Library

Real exploits. Teachable scenes. Reproducible remediation.

Each module dramatizes a real-world vulnerability:

  • Narrative-driven exploits
  • Annotated teachbacks
  • Cornell-style SOPs
  • Copilot Autofix critiques

Built to scale secure coding culture across teams and time.


📝 AppSec Mission Statement

“Security isn’t reactive—it’s cadence, culture, conviction, mentorship, mastery, motion, and leadership.”


📄 Additional Resources


Pinned Loading

  1. skills-introduction-to-github skills-introduction-to-github Public

    Exercise: Introduction to GitHub