As part of my master’s program, I managed the deployment and DevOps pipeline for a student project, ExpensePal, a web-based expense tracker. Early on, security wasn't our focus. We were excited about automating builds with Jenkins, deploying to AWS, and seeing pipelines pass. But a small misconfiguration nearly exposed sensitive information, turning security from an afterthought into a critical concern. In this rookie-level talk, I will share what this experience taught me about integrating security into DevOps workflows. I’ll cover mistakes we made, guidance from mentors, and small but powerful practices; peer reviews, secrets scanning, and IAM hygiene, that improved our deployment process. This talk is aimed at beginners in DevOps and cloud environments. Attendees will learn that security isn’t an afterthought; it’s a mindset. Even newcomers can make a meaningful impact by embedding security into deployment practices from the start.