CISSP Professional Experience Requirement Question
I’m hoping to get an idea of whether I qualify for the professional experience before I dig in to the CISSP. I have many years of experience with IT Security, but it’s never been “direct, full-time security professional work experience” as I have worn other hats and never had the word “Security” in my formal title. I was the “Security Marshall” in my LOB within a large corporation, responsible for implementing and attesting to all of the corporate security guidelines. I’ve been responsible for implementation and management of access control, operations security, network security architecture, and physical security of multiple data centers for many years. I’ve worked extensively with internal and external auditors, including on PCI DSS v2 audits.
So if I have a generic title, like Director of Technical Services, and have security and non-security responsibilities, such as infrastructure, does that rule me out since it’s not “full-time security”?
So if I have a generic title, like Director of Technical Services, and have security and non-security responsibilities, such as infrastructure, does that rule me out since it’s not “full-time security”?
Comments
How long have you been in your role, and how long have you been the "security marshal"? If you've had at least 5 years at the director (technical services) level, I can almost guarantee you'll be fine on getting the full certification without any further experience requirements. All you'll need is someone to endorse you.
So I should be good? Just had some people making it sound like my full-time job had to be security.
You will probably get more and better feedback to this question by posing it in the ISC2 / CISSP forum, rather than the ISACA forum.