Determining a Roadmap
Hello all!!  Wanted to post here and see if anyone could help me make some decisions on a road map to get where I want to be.  My ultimate goal is to be involved with Penetration Testing, Vulnerability Assessments, and possibly some Malware Analysis.  Something along those lines.
A little about me.  I'm currently a Windows Systems Engineer with about 12 years of experience for a decent sized organization (~25,00 users) and I mainly handle the messaging systems (Exchange, Lync, Enterprise Vault), Active Directory, and systems automation with Powershell.  I'm starting to get involved with the patch management process on the Windows side of our department and I try to get myself involved with any sort of security related projects that I can.  Any time I see some sort of lapse in security (sensitive internal websites which should be using SSL, etc) within my organization I am sure to bring it up with the appropriate people.  I would ultimately love to do pen testing and vulnerability assessments within my organization if that type of position ever opened up.  I'm not sure who on our security team is doing that type of work.  Also, I have been using Microsoft Baseline Security Analyzer to scan some of the Windows hosts I am responsible for to ensure there is nothing misconfigured on them.
So that brings me to figuring out how I can make a transition from a systems admin position into a security engineer/pen testing type of role.  One way is for me to get a few security related certifications and that is what I am working on now.  I'm studying for the Security+ exam and will be taking that in the next few weeks.  From there I'm not exactly sure where to go.  I went on Dice and looked at the requirements for a bunch of penetration testing/ethical hacker type jobs and it looks like most are looking for CISSP, CEH mainly with a few mention OSCP, GPEN, GIAC.  Regarding tools the most mentioned ones were Burp, Nmap, Nessus, and Metasploit.  Alot of them also want experience with Perl or Python mainly with some Shell, C++ and other languages thrown in.
I've also looked at the Masters of Information Security and Assurance from WGU because I would ultimately like to get a Masters degree.  The thing I like about it is the fact you get the CCENT, CEH, CHFI, and GIAC G2700 certifications during the program.  I can't decide if I want to do that program or just work on certifications to solidify my knowledge and have something that proves I know the material.
Here is what I am considering:
Security+ (doing it)
SSCP (possibly next)
SecurityTube Python
SecurityTube Metasploit
WGU Masters (CCENT, CEH, CHFI, GIAC G2700 certs)
OSCP
Alot of those positions mention the CISSP but I really don't want to get into that if I don't have to.  I would rather put time into the masters program and some of the offensive security stuff like OSCP, OSWP, and OSCE.  I would really like to do some of the SANS certs but I really can't justify spending that kind of money.  I think I can get work to pay for the Security+ and SSCP certs and they will also give me $1700 a year towards a Masters degree.  The one thing I like about the masters degree is the fact that it doesn't expire like certs possibly can.
I'm just at a point where I kind of know what I want to do but I just need to figure out how to get there and do it in a way that I could transition over from my current position.  Thanks for any input.