I have been a long time visitor of this site and the information members provide is invaluable. I am trying to make the next big step in my career and was hoping that some of you could give me some insight as to what choice(s) I should make.
I am looking at making the jump in the next year into a higher level ISSM job or even CISO of an organization.Background:
- I am 31 and have the role of information systems security manager/officer for my organization.
- I have only about 4 years experience in IT and about 10-12 in industrial, personnel and physical security
- I have CISSP and security +
- Have appropriate clearances
- BS in Aeronautics/AS in Information Technology/ AS in Avionics Systems
Plan: My plan is to obtain a few certs to strengthen my resume and overall ISSM/ISSO experience. I played with the idea of
CEH, but I ultimately think that if I can get the
CISM and
CISA added to my resume it would round my experience out for the next step. I also played around with the idea of the masters, but at this point I don't see it is an absolute requirement as much as I see certs.
While I enjoy playing around with the pen side of security, I just don't agree that the future is as bright in pen testing as it is in GRC work so I would like to stay GRC.
Any advice on what educational path would strengthen my resume for the next step in my security career?