Hello all,

I want to get some certifications and get my base strong before i get into the pen testing and auditing area. Please advice on what certifications i should be acquire. I have my Masters in Telecommunications and CCNA R&S. I am currently working as a Security Analyst (GRC & Questionnaires).

My final aim is to go into Pen-testing and Auditing. What should be my next certification goal to take steps closer towards my aim?

I want to get these certifications because I want to shift to a different company.


    It's kinda hard to give a decent suggestion without knowing more about your background.

    As far as pen testing certs go, you could look into either the eJPT or OSCP. I would recommend the OSCP over eJPT but that's just my personal opinion.
    If you don't have any experience in penetration testing, it's probably not a good idea to start with OSCP. Ultimately, OSCP is where you want to end up, but it's a good idea to build up to it.
    Start with and get comfortable with the basics. Security+ is decent to get your feet wet.
