Hi all,
I am in a very interesting predicament, that I have not been before. In my new IT Security Analyst position, (and one of the reason's I went back to this former employer because, well, they are chaotic) I've been given the opportunity to touch 10-15 security tools, some of which are in our Proof of Concept phase. and some of which are in production.
I am also tasked with Creating Security Controls, Policies, Procedures, and Processes, as well as monitoring, investigating, re-mediating.
I am able to work with IPS/IDS, Malware software like Cybereason, stealth bits auditor and interceptor for monitoring pre-authentication attempts, brute force, breached passwords, sideways movement, all the while being able to create our Procedures for how to use these tools. We are also heavily involved with Securing PHI, and under review for SOC2 certification, with HIPPA to follow again in a few months and HiTrust. There is literally soo much to do with so little time that when I get off, I am having difficulty putting time to pursuing the SSCP, because I can actually do things and grow hands on experience versus the text book knowledge that going through the SCCP would provide.
I will open up some time as I do want to get my SSCP and CISSP before the end of this year, however I am wondering if pushing those back and just doing more hands on work when i'm "off the clock" would be best for my growth. I definitely know my job would appreciate it. We are creating our Security Architecture from the ground up, from access controls, hardening, application requirements, and we haven't even touched end user group policy and techniques to combat rogue software and potentially unwanted programs (our users have local admin rights

) It's more a political battle to get those things put in place.. however just wondering what everyone thinks