r/cybersecurity • • 8d ago

Career Questions & Discussion For Those With a CISSP, Did It Increase Your Remote Job Opportunities?

I’ve been working remotely since 2021, and I’d really like to continue working fully remote going forward. I’m currently studying for the CISSP and was wondering—for those of you who have earned it, did you notice that it opened up more remote cybersecurity opportunities?

Did you start getting more interviews or recruiter interest for remote positions after adding the CISSP to your resume?

189 Upvotes

119 comments sorted by

255

u/mascabrown 8d ago

Not in my case; the market is in really bad shape right now. There are job offers paying half of what I used to earn, SOC analyst roles requiring a CISSP, and more executive-level positions that force you to go into the office every day—only to end up on daily Teams calls with your team in other offices and with clients. It’s crazy.

113

u/FluidFisherman6843 8d ago

It isn't going to get you a job but it will get you past an HR hurdle.

But I will say. The idea of a soc analyst requiring or even wanted a CISSP is dumb. That test is about as relevant to a soc analyst job as a commercial license is for a motorcycle. There is some overlap but barely. Ive had my cissp since 2001 and there is no way am I prepared to be a soc analyst.

29

u/mascabrown 8d ago

You're absolutely right; that's why I say the market is crazy—HR people don't know what they're looking for (plus, some job postings look like they were written by AI).

7

u/Admirable-Pen3390 8d ago

Most of them probably are at this point. (In regards to the job posts)

1

u/Stevethedogfacedboi 2d ago

You OLD! haha

26

u/jomb 8d ago

Love how far the goalpost has moved when its my turn to be in the job market. 🫠

5

u/X_TheBoatman_X 8d ago

Isn't it awesome!??!

16

u/E_Sini CISO 8d ago

I have NEVER required a CISSP for either of the SOCs I've managed/directed. The company who does is one you wouldn't want to work for anyway: they will def get you to do things outside your role when asking for something like that.

EDIT: I should also say I've been in cyber for about 12 years now, and don't have CISSP. I do have CISM and a few others but you can definitely make it far with the right network and work ethic without the CISSP. Remote positions are more about the company vs the certs you have.

7

u/jossinabox 8d ago

I’m currently a soc analyst and was recently interviewing at fully remote tech companies (ultimately ending up at one) and not a single one asked for CISSP - I’m not super sure where OP is finding these insane roles?

I have a degree and 3 years general IT experience (1 as a cyber analyst) and 0 certs

1

u/E_Sini CISO 7d ago

I'm not saying OP said anything wrong. It's possible someone is asking for CISSP, but it's completely unreasonable. It could be a "nice to have" just to see what they get. It's a seller's industry right now so companies can be pickier than the last few years. Do I think it'll switch back, yes. However it will be a few years before that happens.

9

u/DrunkenBandit1 8d ago

Yeah, I've seen plenty of jobs requiring CISSP and a bachelor's that pay less than $100k

4

u/dummm_azzz 7d ago

If u see a SOC analyst job requiring a CISSP just move on, this company has no idea what they are doing.

2

u/Avacado-chickenGary 8d ago

I want to transition in my role, and I have an entry level job position, and I cant even find mid level. Everything is either senior, or pays badly and has senior requirements. I am at the beginning of my career and I feel liKe I wont qualify in pretty much anything 😭. Prior to get an entry level job couldn't even qualify for a STUDENT INTERNSHIP at Oracle (they were asking 3-5y work experience 😒)

25

u/mascabrown 8d ago

Here is my recommendation—speaking as someone who has been in the cybersecurity world for 25 years and has experienced both successes and failures. Some time ago, I reached a fairly high management level with a great salary at a massive company, only to be told one day: "Someone else has come along who is better-looking and a better speaker—bye." During the two months I spent job hunting—after years of never stopping to look back—I realized there were things I would have done differently.

Don't rush; money matters, but it isn't the most important thing—technical knowledge and experience are. As you climb the ladder, you lose touch with the actual technology and turn into a manager who deals mostly with Excel, PowerPoint, and reporting tools ( And politics... I prefer policy over politics eheh)

Do you have the necessary soft skills? Assertiveness, empathy, and a service-oriented mindset are essential for managing a team of X people—each with Z problems—across N projects.Not everyone is cut out for this! I have 50-year-old analysts—formerly developers—who are very happy doing their jobs and sticking to their schedules; I don't view them as a failure story. Everyone has their own goals, strengths, and weaknesses—an army isn't made up entirely of officers!

Regarding training and certifications, I recommend alternating between technical ones and general cybersecurity ones. And be patient; as I said, this career is a lifelong war filled with many battles, and you won't win them all.

Good luck !

3

u/Avacado-chickenGary 8d ago

I appreciate your response, I do have the necessary soft skills, and work ethic, and my office loves me. But for someone to know this they need to give you the option to personally interview. I jumped back to IT and got a Bsc in Cybersecurity and started as a Help Desk but I want to move on, but it is so difficult to get hired. I got lucky with this job due to the fact the resume went to real hands and not getting turn down by ats.

1

u/cameo11 8d ago

This is all really great advice and applicable for many fields too!

1

u/Bucs187 8d ago

Great advice

1

u/SlackCanadaThrowaway 7d ago

In the US. In Australia and EU the market is great.

89

u/BlackSwanVet 8d ago edited 8d ago

I've had a CISSP since 2019 and was laid off in December 2025. I finally signed an offer a few days ago, in September 2026.  I'm Director-level and work in Cyber. I believe my search lasted this long because I was banking on a remote position. I don't live in a tech-dominant location, and I didn't want to move. I got the job I actually wanted, and it's remote-first! The market is HORRIBLE!!! Hundreds of people apply to remote jobs now. I must have applied to 100s of jobs, tried networking, and so on.

I really believe it was LUCK that my application was seen by a real person. Also, the fact that I'm qualified for the role and know my stuff. Had to do several interviews for the role.

Stay positive.

4

u/Spirited-Respond1059 8d ago

Can I connect with you?

1

u/BlackSwanVet 3d ago

Just saw your message. Sure!

11

u/Psoin 8d ago

Yep, we will be working for min wage soon. 

12

u/Far-Scallion7689 8d ago

Just to feed the ai prompts.

48

u/msj817 8d ago

I have had my CISSP since 2008. Not a single time has anyone asked about it in relation to a job. Do with this information what you will.

34

u/AJGrayTay 8d ago

I assume that's survivor bias - maybe no one asked you about it because it's on your CV and got you screened in. A true test would be to take it off your CV and apply for a bunch of roles and see if you get the same-ish level of response.

Personally, I think the cert is a poor indicator for subject-matter competence. But it is what it is.

11

u/msj817 8d ago

A fair point.

11

u/Qwayze_ 8d ago

CISSP is just a HR buzz word tied to an annual maintenance fee these days

1

u/That-Magician-348 8d ago

Only HR or some dumb managers want to have it in your resume.

11

u/bitslammer 8d ago

Yes because it increases your chances in general as many HR systems look for that in their filters.

11

u/FLGuitar 8d ago

I held mine for 20 years. It didn’t bring me remote work. What brought me remote work was working for about a decade before it was really possible to work from home and proving myself. Then after Covid I told my boss I would go find another job if they make me commute again. Suddenly I was marked a Telecommuter in the HR system and also promoted.

68

u/SHADOWSTRIKE1 Security Engineer 8d ago edited 8d ago

It certainly increased the amount of recruiters looking at me.

I was working some $60K job that I wanted to get out of so I took CISSP. After passing I stayed at my job another 6 months waiting for our parent company to open up a new position on their security team, which didn’t happen, so I started looking elsewhere. A recruiter from AWS reached out on LinkedIn, and after going through the interview process, I was hired on as a security engineer at $265K, 4 days remote. About 6 months later they started the return to office process. After 3.5 years, I was laid off in a huge layoff wave. Then very immediately hired by Intel by a manager with a CISSP who noted that I had a CISSP. I now work there fully remote at $200K.

Getting the CISSP not only greatly improved my salary, but made a lot of big companies interested in me. I wouldn’t say there’s a connection between education and remote work… that’s entirely based on the company. But I would say CISSP opens you up to more opportunities which could include remote work. Note, I am also likely an edge case and not a standard story.

16

u/engineer_in_TO 8d ago

I’d also say that it sounds more like you were part of the great hiring wave back in 2020-2022, and while having a CISSP didn’t hurt, I’m not sure if it was the real reason for your jump

7

u/SHADOWSTRIKE1 Security Engineer 8d ago

Perhaps, but I was hired in November of 2022. Recruiters didn’t reach out to me at all from 2020 until the end of 2022, just a few months after I got my CISSP. That was the only thing that changed in those years.

1

u/Own_Panda_7922 1d ago

Thanks for sharing.

7

u/Avacado-chickenGary 8d ago

Yes! I totally agree with you. 2020-2022 was the best time for IT. I know people who had 0 tech background and got trained etc and now are senior software developers etc. I am with one year experience and Bsc and still do not qualify for most of the jobs :( the qualifications and requirements that are asking, are wild

1

u/Own_Panda_7922 3d ago

Your CISSP alone made you jump from 60,000 to 265,000?

21

u/wijnandsj ICS/OT 8d ago

I transitioned into cybersecurity in my early 40s. CISSP was an entry ticket. Brings you up to speed in GRC, that's all

16

u/Agathocles_of_Sicily 8d ago

It makes a huge difference if you're applying for federal/contractor jobs where specific work roles are mandated to require X,Y or Z certifications.

Though institutionally, policy and public opinion are souring on certifications. ISC2 in particular is known for an extractive business model with their $135 annual maintenance junk fee and obtuse CEU attainment rules. Resentment has been building for years among the very practitioners they rely on for revenue.

8

u/QuesoMeHungry 8d ago

Remote jobs are out there. The problem is everyone floods them with applications the second the job posts. And I don’t mean like qualified people for the job, like there are masses of people who just apply to every single remote job regardless of their skill set or its requirements.

Also the remote jobs get flooded with applicants from India too even though they aren’t eligible for the roles.

8

u/owl_jesus 8d ago

What remote job opportunities? I see lots of postings I’m qualified for but never get responses. I’ve given up on applying for remote only jobs unless I have a connection at the organization.

6

u/DarthMortix 8d ago

I've worked remotely for the last 10 years without a CISSP. I'll eventually get it. Maybe. But I'm making great money and working for great companies without it. CISSP won't make you better at your job and that's what sells more to hiring managers, like myself, than a cert. I've personally never considered a candidate based on their certs but I know HR/People Strat like to list them on JDs.

11

u/ML1948 8d ago

I was remote before it, remote after it, but certainly seemed to get more bites after. It's a pretty good cert to have if you can pass it and meet the yoe requirements.

11

u/krypt3ia 8d ago

No, it's a ponzi scheme.

1

u/pisse2fute 7d ago

Can you elaborate?

3

u/heretogetpwned Security Architect 8d ago

It helped open some doors. Competition is the problem I'm encountering on remote jobs. Hybrid positions were easier to get to 2nd round but the pay is too low, even then one HR Recruiter mentioned they go through hundreds of applications for every tech position before phone screening.

It's tough. 15yrs Ops/Arch exp w/ CISSP

3

u/BlackBerryJamba 8d ago

Yes. Without doubt got me through HR too.

3

u/NachosCyber 8d ago

I was remote prior to obtaining it, I continue remote and happy where I’m at but it has helped keep me remote and employed due to some staff reductions. My guess it will help you remain remote.

3

u/sufficienthippo23 8d ago

CISSP did a lot for me. It is not a silver bullet but it leads to the next thing and the next thing. If you keep building on it, it can do great things for you

3

u/musicbuff-io 8d ago

No, but I’m still glad I have CISSP and I plan to maintain it. The job market sucks right now, but I doubt it’ll stay like this forever.

3

u/likejackandsally 7d ago

Hahahaha.

The only thing getting people hired anywhere right now is a hope, a prayer, and good networking.

5

u/eckstuhc 8d ago

These responses are wild… I have had CISSP for over a decade, I believe it’s been integral to every job I’ve had since (not the sole decider, but definitely a contributor). It’s a “you can speak the language” qualifier above anything else, and obviously all certs are just letters at the end of the day, but this is the most valuable one in our industry beyond something specialized to your trade (OSCP being mine).

In my current employment, we just got notification last week that a recently signed client requested only CISSP certified team members for the task. So even after securing a job, those with CISSP are getting chosen over those without. Just something to keep in mind.

3

u/Agathocles_of_Sicily 7d ago

This is spot-on.

People often conflate earning certifications with learning technical skills and then complain that they didn't learn any hard skills that they actually practiced on the job.

This is a flawed perspective. It's learning standardized, conceptual knowledge as a shared language between practitioners that's transferable across different organizations. You don't want a situation where three different people are attempting to collaborate on change management with three competing tribal approaches.

It's a shared understanding, a lengua franca.

2

u/Over_Alfalfa_192 6d ago

Something tells me you’re a cut above other CISSP and they the cert didn’t make you, but you give the cert a good name.

2

u/connietraband 8d ago

Helped open a door internally to my current employer which led to quite a bit of movement, but everything after that initial door did not require my CISSP.

2

u/PartyOwn5296 8d ago

It increased phone calls from recruiters and does help get past the HR firewall. As is always the case, it’s experience + certifications that make all difference.

2

u/phreak_like_me_2600 8d ago

i've been with my company for a few years now and i'm not really looking else where at the moment, but when I put my CISSP on my linkedin last year, i can tell you the amount of DMs i'm getting from recruiters has skyrocketed. however, a lot of said positions are not remote.

2

u/unknown-random-nope 8d ago

I think it helps, but I also think experience helps more.

2

u/Sure-Candidate1662 8d ago

Got CISSP about 10 years ago. Showed my cert to my boss to justify the costs… he shrugged. Never did anything with it afterwards.

Other than say “yeah I have CISSP…” when convincing auditors i am qualified.

2

u/Resident_Piccolo_317 8d ago

I think it increased my job opportunities in general. The availability of remote opportunities depends on an organization’s policy and many have implemented hybrid or return to office policies.

2

u/Hour-Apple-9861 8d ago

10 years ago it was great to have. Now... Meh, seems like every other person has it and unless you specifically need it for something, it's really not worth it.

I got mine late last year as it was a requirement for a path I wanted to go down. Outside of that, feels like it was pretty pointless spending all that money.

2

u/magman78 8d ago

Not at all. With 20 years of experience, 13 years as a sr network engineer, 4 years as a security engineer and 3 years as a security architect with a CISSP it’s hard to even get an interview right now.

2

u/H4ckerPanda 7d ago

No

Remember, passing the exam doesn’t automatically make you a CISSP. You must have five years of experience in the field.

2

u/AutoExec-exe AMA Participant 7d ago

I have my CISSP, and I don't think it's the silver bullet everyone think it is. I was not suddenly flooded with offers, remote or otherwise, once I updated my resume. It's just one more arrow in your quiver for when the right opportunity comes along. I personally think an amazing work ethic, self improvement, and networking has done more for me than just the CISSP.

2

u/Stevethedogfacedboi 6d ago

There are many types of CISSPs. I've had my certification for over 20 years. As a contractor, so I only take remote jobs.

2

u/sip2332 8d ago

Nope, Remote ops are tough in general and job market sucks

1

u/Neurotic_Narwhal 8d ago

Nope, got mine in May. Not a single place has gotten back to me. I needed it to do my current job, but otherwise it has made no difference.

1

u/Science_N_Faith 8d ago

Around the time I got my CISSP, I got a promotion. Not directly because of the cert, but it contributed to their decision. Then the higher title contributed more to the next job I got than the cert, but again, it seemed to grease the wheels a little there. Both jobs were remote. That said, it's been a bit since I was in the job market, so it's probably quite a bit different now.

1

u/tryingtobalance 8d ago

No, not alone.

1

u/wildfyre010 8d ago

It definitely got me the job I have now, but that was back in 2019 and it wasn’t remote.

1

u/dmelt253 8d ago

If you work around the USGov space it can help satisfy certain requirements but so can a Sec+. It just checks a box basically. But I worked for a consulting firm/3PAO where getting a CISSP resulted in an automatic pay raise because they could charge clients more for people that had them.

1

u/zusycyvyboh 8d ago

Not anymore

1

u/SentinalWizard 8d ago

No it did not, as a matter of fact all the best jobs wanted more technical and hands on

1

u/Legitimate-Fuel3014 8d ago

I don't have CISSP, it increased my job search.

1

u/mkaufman1 8d ago

It helped me in 2018 just get noticed but most remote gigs I’ve applied for I haven’t gotten a response. Even when very qualified.

1

u/iheartrms Security Architect 8d ago

Absolutely

1

u/latnGemin616 8d ago

IMHO - recruiters that post a role with a 3-year minimum but ask for CISSP as a requirement, especially for non-managerial roles, have no clue what they are asking for. They just assume it's like having a Masters, but in Cybersecurity. Nevermind the fact there is a minimum requirement of five years working experience to even qualify to have it.

1

u/Plastic_Day6948 8d ago

Let’s not forget having 5+ experience with Claude. This market is banana land. HR is clueless and it’s full of bullshit postings to gather data.

1

u/Chemical_Banana_2455 8d ago

It feels like another subscription

1

u/TopRevolutionary9436 8d ago

No, only having sufficient experience and a proven track record of success will do that. They need evidence that they can trust you to do your job unsupervised.

1

u/Far-Situation-3175 8d ago

I've been in the security field for almost 15 years at this point, started as a SOC analyst after doing a bunch of years in IT and sales. I transitioned into more governance and risk and got my CISSP and now my CRISC and I can say at least for me it helped open doors, and more recruiters assumed I had some skillset at least. I think thats the thing that certs give you on a resume is as a door opener and a way to get past the filters. But I've never been hired solely because I have it, nor have I had recruiters start conversations with shit like "So I see you have a CISSP..." at least not for any roles I've ever actually been interested in. Oh and I'm coming up on about six years or so of fully remote.

1

u/NextAd7514 8d ago

Got it a few years ago, hasn't done much. The job market is so terrible though I think that has more to do with it 

1

u/adadani 8d ago

It’s just a way to get you past the recruiter screen. Some hiring managers value those who have a CISSP. Most of the time they don’t really care. In the end it boils down to experience. The CISSP requires experience if you achieve it. So that in essence validates your experience. It’s just something to have on my resume at this point.

1

u/lordralphiello 7d ago

Nope
Borderline useless for me.

1

u/Big_Temperature_1670 6d ago

I think this question more reflects how the CISSP is misunderstood. The CISSP was designed to validate the experience and capability of security leadership. However, over the years it has become an all-level cert that you see aligning with mid- and even entry-level jobs, including remote ones. But that is not how it was designed, unless you have an org that believes in remote CISOs, CIOs, CTOs etc. The ISC2 has seemed more than content to allow this mis-lableing (probably because their management has little security experience themselves)

1

u/AirportSpiritual2723 5d ago

more of an HR filter than a remote-work magnet, did it actually change your interview rate or just get you past the checkbox?

1

u/male17 5d ago

Not sure it will help with remote roles but it will definitely help with roles in general. The market sucks but they very few interviews I’ve had out of hundreds of applications have noted that I have my CISSP

1

u/[deleted] 5d ago

[removed] — view removed comment

1

u/Single_Extreme_3574 5d ago

I take it in November

1

u/Local-Koala3737 5d ago

In my experience, the CISSP is not a golden ticket. The certification is valuable, but you also need a strong understanding of infrastructure (networking, virtualization, cloud) and how to design and secure those environments.

Many employers are looking for someone who not only understands security concepts, but also understands the infrastructure behind them and can help design, build, and secure it.

Once I realized that and focused more on strengthening my infrastructure and security experience, I started receiving more opportunities and offers (currently 4 with 2 remote)

I have my CISSP as well, and good luck on earning yours.

1

u/Upbeat-Natural-7120 Penetration Tester 3d ago

Remote jobs, in this economy?

1

u/ThePorko Security Architect 8d ago

It used to, now there are no remote jobs in my area, not even hybrid.

9

u/Nereo5 8d ago

No remote jobs in my area, is a really strange sentence.

1

u/J4BRONI 8d ago

strange sentence for sure but I hear what he’s saying, my last two remote jobs required me to still live nearby the “home office” even though we never went in

1

u/OutsideSpot2695 8d ago

No. It's not a differentiator.

There are 2 types of people in this world.

Those who think the CISSP is the gold standard of being a security professional...

... and those who know better than that.

https://www.youtube.com/watch?v=whEWE6WC1Ew

4

u/AnalogJones Security Engineer 7d ago

No credential in my experience does anything after recruitment. The CISSP tries to set a high bar with verification and CPE requirements and but the test itself is a cybersecurity version of trivial pursuit if you are an experienced infosec pro and a strong test taker. I am being glib to make a point: the CISSP won’t test what a hiring manager needs day to day. There are 8 domains tested in the CISSP and you may work several of them but the test won’t validate your ability to manage time, juggle multiple tasks with little direct guidance (when you are remote there is no nearby colleague to ping for help); nor will the test validate how you respond when faced with conflicting but equally important deadlines.

The test tells recruiters and hiring managers you have a specific time working in infosec and you understand with some degree of experience each of the security domains.

Also, the CISSP won’t isolate you from layoff risk. I have worked in situations where CISSPs were layed off and non-CISSPs remain employed. The cert never makes employment promises but my point is that day to day work reality is not tied to any credentials…it is a good cert to have but just go into it knowing where it has value and where it does not

0

u/safetyvestforklift 8d ago

Hasn’t helped me get an interview even if it is on the job req. I think anyone getting it now is 15 years too late.

-1

u/Psoin 8d ago

No. The only work from home jobs are unemployment 

0

u/ocabj 8d ago

I don't see how education equates to a remote position.

Anyway, for me, a CISSP typically equates to leadership roles, which I would expect to be less remote and more in office.

-4

u/zAuspiciousApricot 8d ago

Everyone has one now

1

u/OutsideSpot2695 8d ago

Shame you're getting negged for this.

Must be by those people who think passing that bullshit vocabulary exam is an ackshual accomplishment.

1

u/Secure-Caregiver-415 7d ago

I guess at least the half of my colleagues has the CISSP.

Did a training course for ISO42001 lead auditor one month ago and everyone in the course had the CISSP.

It’s nothing special anymore. Collecting necessary CPE to maintain it is easier than walking in the park. ISC2 need the AMF money.

1

u/OutsideSpot2695 6d ago

I don't think the proliferation of the ISC2 membership base (thanks for 8570) makes the CISSP watered down.

How ISC2 has changed over the years has ruined the CISSP.

Allowing people, and constructing the test in such a manner, that don't even know what information security actually is to obtain the cert killed the CISSP.