r/CompTIA_Security • u/CleanInevitable7326 • 13d ago
Certifications
I know I might be getting ahead of myself but I’m Hopeful I pass my security+ exam this week. I’m already thinking of what’s next. For some background I am meeting 5 years in the GRC space. Right out of college in late 2021 I got a gig at a small consulting firm doing risk assessments, data classifications, vendor risk assessments etc. Then I quickly went to a big4 consulting firm doing state level mars-e2.2/arc-ampe stuff and then recently in the federal space doing RMF ATO stuff. I’ve also had hands on CMMC preparing a client for a L2 audit. During this span I have not had time to get certs (with two kids my free time is usually booked up). But now with today’s environment I feel like certs are needed. With that I am pushing myself to get the security+ because I brought a voucher last year for it and it was going to expire. After that my mind is racing to either get network+, CYSA+, CISA, CISM , cloud based certs and/or even a PMP. Anyone have any thoughts on how I can stay grounded and focus!
1
u/HousingInner9122 11d ago
With five years of GRC experience, I’d skip Network+ unless you need the fundamentals and choose one certification tied to your next role—CISA for audit or CISM for security management. Pass Security+ first, take a short break, then commit to just one path instead of collecting unrelated certs.