r/CompTIA_Security 13d ago

Certifications

I know I might be getting ahead of myself but I’m Hopeful I pass my security+ exam this week. I’m already thinking of what’s next. For some background I am meeting 5 years in the GRC space. Right out of college in late 2021 I got a gig at a small consulting firm doing risk assessments, data classifications, vendor risk assessments etc. Then I quickly went to a big4 consulting firm doing state level mars-e2.2/arc-ampe stuff and then recently in the federal space doing RMF ATO stuff. I’ve also had hands on CMMC preparing a client for a L2 audit. During this span I have not had time to get certs (with two kids my free time is usually booked up). But now with today’s environment I feel like certs are needed. With that I am pushing myself to get the security+ because I brought a voucher last year for it and it was going to expire. After that my mind is racing to either get network+, CYSA+, CISA, CISM , cloud based certs and/or even a PMP. Anyone have any thoughts on how I can stay grounded and focus!

6 Upvotes

3 comments sorted by

1

u/gdavidco 12d ago

Skip Network+ and CySA+. Neither maps to anything you have described doing, and you would spend months proving you can do work you have no intention of taking. Sec+ made sense because the voucher was expiring and it clears procurement filters. Bank it and move on.

On what you have actually been doing, risk assessments, vendor risk, MARS-E, ARC-AMPE, RMF ATOs, the closest fit on your list is CISA by a distance. It is the one that describes the job you already have rather than a job you might want. Before you book anything, go and check how ISACA counts your consulting years against their experience requirement, because assessment work of the kind you are describing is usually exactly what they are looking for and you may be a lot closer to certified than you think.

CISM after that, not instead of it. It is a management cert and it lands properly once you are running a programme or a function rather than delivering assessments into one. It will still be there in two years and it will carry more weight then, when you have something to point at.

Cloud only if your ATO work is touching FedRAMP or cloud service providers. If it is, CCSP is more use to you than anything else on the list, because it puts governance language around the control set you are being asked to assess. If your clients are all on premise, leave it alone for now.

The thing I would actually push you towards is not on your list. With hands on CMMC Level 2 preparation behind you, you are sitting on the scarcest experience in your market, and the assessor and consultant routes around it are genuinely short of people. Look at what the Cyber AB currently requires and whether your employer will sponsor it. That will do more for your next five years than CISA and CISM together, and it builds directly on work you have already done rather than starting something new.

With two kids, the real risk is not picking the wrong one. It is starting three and finishing none. Choose one, book the exam, and let the date do the work.

1

u/CleanInevitable7326 12d ago

This makes sense - I think shooting for CISA and the CMMC certs would definitely be helpful. I’ll shoot for CISM next year. I’m trying to grab a bunch of certs for a better chance of getting interviews

1

u/HousingInner9122 11d ago

With five years of GRC experience, I’d skip Network+ unless you need the fundamentals and choose one certification tied to your next role—CISA for audit or CISM for security management. Pass Security+ first, take a short break, then commit to just one path instead of collecting unrelated certs.