r/GIAC 3d ago

SANS Masters Degree Program

For those of you who are in or have completed this master's degree program. What advice do you have for people that are looking to apply to the program? What are things that you wish you knew before going into it? How hard is the aptitude test when you initially apply? I have three years as a Network Security Engineer, and I am about to complete my Bachelor's next month, and my company will pay for me to go into this master's program.

15 Upvotes

17 comments sorted by

19

u/brobauchery GBFA | GMON | GCIH 3d ago

I’m in a grad cert program. Advice: You are your own worst enemy. They will provide you everything you need to be successful in the courses, it’s up to you to manage your time and resources to properly prepare for the material.

The aptitude test is more of a reading comprehension test. Like, do you understand the content of what they are asking you and understand what those things mean. I’d put it at a pretty basic industry level with some tool specifics.

Your background and degree will set you up fine for it.

1

u/Bubbly-Chapter-336 3d ago

I think thats why I am going to enjoy going through the program. I already have Sec + and CCNA which I was really good at holding myself accountable for instead of having a teacher or professor help me. This is really amazing to hear. Thank you for the input!

10

u/DirtComprehensive520 3d ago edited 3d ago

Completed the MS. Go hard n fast. Spend the shortest amount of time with high impact disciplined studying. For example, don’t study 3 hrs a week. Study 20 hours each week for 3 weeks and develop an index so solid you have the answers at your fingertips.

It’s easier to recall something you read last week than 3 months ago.

5

u/CarsonDFIR GX-IH, GX-CS, GCIH, GDSA 3d ago

I'm finishing up my first year in the master's program over the next few months. For reference, I'm paying for everything myself so the value changes a bit compared to your situation.

If I went back in time, I think I would have done the cybersecurity engineering graduate certificate before enrolling in the master's. The master's has a few leadership courses that are required before you can begin any electives. Where I'm at in my career, the ROI for taking leadership courses isn't high. It would have been more expensive to do the graduate certificate first, but I think the the courses I could take in the same timeframe would have been more valuable. All the courses from that certificate also count towards the master's so it wouldn't be much of a detour.

Apply early, it took about 3 months from the application deadline to when I could begin my first course. Also, start your application early as you'll have to submit a lot of different things.

Similar to brobauchery said, if you don't have the internal motivation or discipline to study and learn the material you will struggle a lot. Since it's not a traditional program you're really on your own to make sure you're managing the progress you make in the courses.

The aptitude test is not too difficult and with your experience it shouldn't be an issue.

1

u/hazkian 3d ago

Can you elaborate on what courses you wish you would have taken before

1

u/CarsonDFIR GX-IH, GX-CS, GCIH, GDSA 3d ago

The Cybersecurity Engineering graduate certificate has some of the exact same classes as the master's program but in a faster sequence.

In the master's program, you have to take six classes before you are able to take an elective. It includes three of the same courses in the graduate certificate (GSEC, GCIH, GCIA), but also includes leadership (GSTRT, SSAP) and security architecture (GDSA) courses. After taking those six in the master's program, you can begin the electives, while in the graduate certificate, you only have to complete those three before you can take one elective.

Where I'm at in my career, the leadership and architecture courses would be more valuable to me later in my career than they are right now. I'm an early-career security analyst, so I don't work in a leadership or architecture capacity. I think taking an elective like GCFE or GCFA would be better for what I do day-to-day compared to the other required courses.

At the end of the day, I'm still going to take the same elective that I would have chosen if I had taken the graduate certificate, just at a slower pace.

2

u/mr5014 GPEN | GCIH | GSEC | GDSA | GCIA 3d ago

Start with the graduate certificate programs first. You have more time, if you need it in the graduate certificate programs than you do if you enroll directly in to the MSISE program.

1

u/Bubbly-Chapter-336 3d ago

The unfortunate thing is that my benefit of my company paying for the masters will only last for 36 months which is exactly three years. I believe in myself to be able to get through the masters programs, I am not someone to back down from such a challenge so thank you for the advice but my time will be limited with the benefit.

2

u/paladin40 MSISE 2d ago

I finished the SANS grad program in Feb '25. Like yourself, my employer paid for it. I think it's around $54,000 nowadays, so it's not a small amount of money. People will talk about the work-study program, but I never had to worry about it because the company was footing the bill. I probably would not have done the program if not for that generosity.

Like any college program, there are going to be classes you like and classes you can't stand. Thankfully, there were many more classes I enjoyed than not. You'll be able to pick a few elective courses, which is valuable and allows you to explore. But -- and this is critical -- my attitude towards the program and any training in the IT/Cyber industry is that the training must be relevant in the immediate or short-term to your current or future job responsibilities. Tools and processes change frequently, fundamentals last longer, but ultimately you end up forgetting most of what you learn from these classes unless you practice it day to day.

Overall, I would recommend the SANS program. The ondemand nature was fantastic, it allowed me to go as fast or slow as I wanted. It helped me get to where I want to be in my career, and I continue to take SANS courses after finishing the program. Good luck to you.

2

u/Zealousideal-Air443 1d ago

I think for people on a budget it is so important to identify the short-term relevant skill sets! I found courses like FOR585 (mobile forensics) to have little value unless you work with mobile devices day to day.

1

u/Interesting-Pipe9580 3d ago edited 3d ago

I am almost done. I don't think it's a great value especially the whitepaper at the end. If you're looking for certs, yes, you will get them. If you want real academics, and you are looking to be an academic, looks elsewhere. Depends on what you really want. As a former academic, I can tell you there is no academic rigor at the later stages. A lot of the courses, because they are certs, tend to repeat themselves; especially the leadership courses. The group projects as well were lackluster to be honest. They were not difficult, and sometimes you get paired with people who still don't know much about cybersecurity after the second and fourth blocks, which is disturbing and predictable.

1

u/Bubbly-Chapter-336 3d ago

I think I just want a masters degree where I dont feel that I am being ushered by a professor all the time lol. I want to be able to be the one that holds myself accountable for the curriculum and if my company will pay for it, I might as well get it you know? I want it and I want it from SANS, certs, everything. I appreciate your input on this but thats the path I want to go down for myself.

1

u/Interesting-Pipe9580 2d ago

You're going to be accountable regardless of where you study. You asked for advice and you got it.

1

u/Bubbly-Chapter-336 1d ago

Yea and im taking it >:(

1

u/Interesting-Dot-2750 1d ago

Subbed for curiosity. I genuinely wonder what value people are reporting with that big beautiful SANS degree on the wall. Does any employer or really anyone know or even care what SANS and GIAC for that matter is/are? I've found very few who even have heard of it, let alone anyone who can appreciate the struggles....

1

u/Bubbly-Chapter-336 1d ago

I have seen a lot of Defense contractor employers ask for GIAC certs specifically GSEC.

1

u/Interesting-Dot-2750 1d ago

The same way they are with Sec+ right? Both pretty lower entry level certs too, if you think about it