Is CISSP for me?
I have reached a point in my career, where I believe I should start transitioning into a more senior/management role. The field of the network security really interests me and I would like to make it my primary field of expertise. I am looking for a certification that would give me a "jump start" into that field. At first I was thinking about OSCP but after reading these forums for quite a bit, I am not so sure any more and started thinking about CISSP as more beneficial. I read Keatron's post about the progression and I think more or less followed it.
Here is a bit of info about my background and education.
I started out as a help desk in USAF in 2000. After 4 years, I got out and found a civilian job as a help desk which eventually turned into a system admin. For the past 5 years, I work as a network engineer. Since I am with a relatively small company, I am the only person who supports the whole infrastructure and my responsibilities are very diverse. I support two colo's and one office locations including about 18 Cisco routers and switches, 6 Cisco ASA, IPS and around 70 servers.
My security related experience: DMZ and DR design and implementation, firewall management, IPS configuration including custom signatures for our in-house app (we process commission's for traders), VPN's - dial-in and site-to-site, implemented RSA SecurID, preparing my network for compliance and security audits, vulnerability scanning, patching, a bit of pen testing my network perimeter, GPO's, server hardening, logs and traffic monitoring. I also wrote policies for the backups, DR, router and server hardening with checklists and etc.
Education: BS in Computer Science, MS in Telecommunication Networks, CEH, CCNP Routing & Switching, CCNA Sec. Currently, I am 1/2 into CCNP Sec - still have VPN and Secure exams left but I will sit for them by the end of October (doesn't take long to study if you work with the technology every day).
Questions:
1. Given my experience and education background, is CISSP a next logical step for me? Or is there any other certification which would be better suited?
2. I know some of the posters here are in the senior/management positions. Would you hire me if I had CISSP?
3. I am afraid that coming from a small company would lower my chances of getting a job in a big corporation. Does my fear have a merit?
Thank you for reading and your comments in advance.