So after spending about 4 years doing Help Desk, about 4 years as SysAdmin, and a bit over three as an IT auditor, I'm thinking about shifting to Pen Testing. I want to do more hands on with security vulnerabilities than the theoretical analysis I have been doing. I have my CISSP, CEH, CISA, MCP for Server 2003, and plan to finish CIA (Certified Internal Auditor) in February since I only have one more exam to take. I also have a BA in an unrelated field.
For 2014 I am torn on what would make me a more attractive candidate. I am going to take the OSCP for sure. After that, I have a few options. Should I do the WGU MSISA, or would it be better to self study and challenge a few SANS certs? Or would it be best to get some certs from ECCouncil/SecurityTube/eLearnSecurity? Or would it be better to simple sandbox, practice, and maybe take a few courses from someone like Joe McCray (
Strategic Security ++ Pentest Lab Access)?
A second consideration is timing. I may be stuck in my current position due to a bit of job hopping. How bad does this look?
Helpdesk - 3 years at a University
Sys Admin - 4 years at a University
Sys Admin - 1 month at a small company (I was fired. I leave this position off of my resume, but my employment gap may come up in interviews)
Unemployed 3 months
IT Audit/Compliance/IT Risk - 2 years at a large publicly traded company
IT Audit/Compliance/IT Risk - 10 months at one of the Big 4 (Deloitte, PwC, EY, KPMG)
IT Audit - Current - 3 months, medium sized financial brokerage
I'd prefer not to stay in my current role longer than 1.5 years.
My third consideration is pay. I anticipate a pay cut in switching roles, and can afford a 30% pay decrease. I checked glassdoor and pay for penetration testing positions is not a widely reported number it seems. Any thoughts on typical pay for new pen testers with security experience?