Hi all,
I'm currently in a role where I conduct cyber crime investigations, often with digital forensic work. Years ago I was a web developer, doing things like some server management, as well as PHP/MySQL e-commerce website work.
I've got good knowledge of linux, networking, numerous protocols. I'm very good with command line within Linux, less so in Windows as I don't use it very often.
In around 18-24 months I'd like to move into a more
penetration testing/IT Security/Cyber Analyst role. I realise these are three different areas but some of the positions I've seen have some similarities and it often depends on your knowledge as to where you can go.
In the next 12 months I have several courses booked:
- MCSA - ongoing with exams and learning
- ISO 27001 Practitioner (3 days)
- Certified Forensic Investigation Practitioner (5 days)
- Certified Forensic Investigation Specialist (4 days)
- Certified Security Testing Associate (4 days) - includes stuff like packet sniffing, target analysis, attacking windows/Linux, etc...
- Certified Security Testing Professional (2 days) - Injection, Cross site scripting, and other similar techniques
- Certified Malware Analysis (4 days)
- Certified Secure Coding for Software Developers (2 days)
Some of these courses are advertised as good preparation for the CREST exams, including pen testing, and also for CEH exams which I hope to do, maybe next year depending on how I get on.
Questions
- Is GIAC GPEN a good certification to get as I've been offered the chance to do that
- I did try to get on the CISSP course although at present this is not a possibility, but I will probably try again next year as it looks to be a lot of work and learning involved.
- Any advice for my aims at moving into pen testing/IT security roles?
- Any specific certifications I should concentrate on getting?
Thanks everyone