NovaHax wrote: » Well, you got the prerequisites for OSCP covered. The only expectation there is an understanding of TCP/IP and Linux. Honestly, having done all three...you'll get a lot more out of that one that CEH or CISSP anyways.
Cold Titanium wrote: » https://www.youtube.com/watch?v=8DZkpynFhak
W Stewart wrote: » If I remember correctly, the cissp requires 5 years of experience in a specific domain of security. There are something like 10 domains but I haven't really looked into it. If you've been working with firewalls for 5 years then that should count. I've heard some people were able to use experience as a security guard to count towards the physical security domain. If you're not entirely sure which cert to go for and aren't sure if you have the experience for some of the security specific certs then I'd consider ccna security and ccnp security. Those are two certs that should be well respected and don't have specific experience requirements.
yzT wrote: » What are employers looking for? CISSP What is the better cert? OSCP.
gui4life wrote: » I want to help my company build up their security posture, identify areas needing improvement, and mitigate risks by implementing systems/policies/countermeasures. I foresee an even and good blend of managerial/pentest/tech work (such as implementing IPS), etc.
da_vato wrote: » Ultimately you need to pursue a cert based on the job you want to do (because that is the knowledge you will need) not chase a cert based on what people think is better.
da_vato wrote: » CISSP is a defensive posture while OSCP is a offensive posture (I suppose technically you can throw CEH in this category also). Based on what you said I think CISSP would be a better ROI for you since you want to guard your company. If you wanted to work for a firm that tests other organizations security posture I would say OSCP. Ultimately you need to pursue a cert based on the job you want to do (because that is the knowledge you will need) not chase a cert based on what people think is better.
diggitle wrote: » BS information security --> Security+ ---> CEH (currently here) ---> SSCP ---> one or multiple (OSCP | GWAPT | GPEN | eWPT | eCPPT)---> CISSP
diggitle wrote: » Dice.com shows only 16 jobs for pen tester. Web app shows 19,608. So I'm going all out web app.