Completely brand new to information security....career paths?
Ok, I am completely brand-spanking-new to IT security, and I just want to get a measure of where I am, and where I should go.
My story:
I worked for a couple of years after college as a backup technician for a small digital media company. It was pretty dead-end work (seriously, I did nothing 80% of the time), but eventually the company was bought by a much, much larger company, and I got recruited into the infrastructure team, even though I had zero IT experience (except for my one little backup server).
That was about nine months ago. Since then, I've done quite a bit of networking work. Anyway, I *think* I'm about ready to take my CCNA (and hopefully followed very soon after by CCNA Security), but obviously that's just the first step.
The problem is that although I enjoy what I do, I feel little excitement about the subject of networks itself. I want to learn more about networks, but I look at network expertise as a means to an end: essential to understanding the eventual big picture, but not necessarily something that represents what that big picture is.
Security, however, fascinates me because, by its very definition, it involves protecting against or combating a tangible, directed threat perpetrated by thinking humans, rather than protecting against arbitrary technical problems. More than that, I see a security career path as one that emphasizes "big picture" understanding, which I'm quite good at, yet still focuses on specific overall goal.
The problem I'm facing is that, being so new to IT in general (remember, only nine months' experience, three of which were probationary), I have no sense of context or perspective, especially in the field of information security. I know that security in general is essential, and I know that the general concept of and driving motivation behind information security are things that excites me, but I don't know what specific career paths or specializations I have to choose from, nor do I know what certifications or education will help me along those paths.
Anyway, that's my story. I wanted to hear from some of the people here some of their experiences, and some tips and advice for a brand-new member of the IT community interested in security. I'm especially interested in the (ISC)2 certifications, as well as the value and significance of advanced degrees in information security (I've been looking at the CISSP qualifications). But I need specifics.
And please, if you see me making misconceptions about the field that need to be corrected, say so!
EDIT: Read a few more threads on this forum, and I guess if business continuity is part of the overall security field, then I'm not *totally* new at it. A big part of my current job is planning short- and long-term backup and disaster recovery policies for our new POPs. Still, you know the adage "Prevention is better than a cure"? Disaster recovery to me seems more like a cure, and I think I'd rather be working on prevention.