Parametised queries are the big one which usually takes care of most of the risks actually.
Beyond that, I’d say stick to least-privilege accounts (avoid running queries as root), validate inputs even if they’re parameterized, and since you're just starting out, using an ORM is a safe shortcut since it handles most of the heavy lifting. For practice, DVWA or similar vulnerable apps are great to learn what not to do. Someone with more experience in this space might be able to pitch in some more or improve upon what's mentioned.