Greetings ISC2 community! My name is Jake, and this is my first post here. I would like to pick the brains of the fellow ISC2 folks here for ideas on where to go cert-wise. First, some context: I had done all of the IT-related classes in my high school days, then shifted to pursuing my bachelors in CompSci, Software Engineering focus. I complete my program this December and will have my B.S of Computer Science soon. In terms of career, back in 2023 I had gotten my first IT support job with the only experience being my high school help desk class. It was a massive breakthrough for me. It focused on supporting software development consultants. I had then transitioned into an IT Operations Coordinator position, which I currently still work as.
Despite studying with a focus on Software Engineering, this job (which I have held for over a year now) has shifted my interests into IT operations and management overall, especially with considerations for security. This led me to study for the CC, of which I passed the exam earlier this month! It is my first certification of any kind, and it was easy enough because I had taken a security fundamentals course in school a few months prior. I feel I have a strong grasp on all the fundamentals, at least as the CC identifies them.
All of this is to ask: what would be some ideal certifications to train on going forward? I am not opposed to sticking and growing as an IT Manager, but I am still interested in security operations overall. I was thinking the CGRC would be an ideal next-step with that in mind. I am open to hearing some opinions from the community, especially if anyone has experienced a similar career/learning pipeline to mine.
Thanks!
If management is what you are interested in, I would recommend looking at governance, risk, and compliance related work.
Take a look at ISACA and their CISA and CISM certs, maybe also CGEIT and CRISC.
ISC2 has their CGRC cert, but its not well known.
Take a look at learning various security frameworks such as NIST CSF, NIST RMF, ISO/IEC 27001, and CIS Controls.
Take a look at SANS Institute's leadership courses and certifications.
And you might consider some kind of MBA course or program....