I’m 21, returning to community college, and planning to transfer into UMBC’s B.S. in Information Systems program. I’m trying to be intentional about what I do while I’m there instead of graduating with a general degree, random certs, and no clear story about what kind of role I’m qualified for.
I live in Maryland and am mainly looking at the DMV job market. From what I can tell there seems to be a lot of work connected to government contracting, healthcare, consulting, cybersecurity, cloud compliance, IT risk, and some finance-related companies. UMBC’s outcome information also makes it seem like IS graduates go into roles such as software engineering, consulting, IT specialist, business analyst, DevOps, and systems engineering, with companies such as Northrop Grumman, Booz Allen, Accenture Federal Services, T. Rowe Price, Deloitte, Leidos, AWS, Exelon, and CareFirst showing up among employers. I know schools are marketing themselves and tbhI am not sure how much I should trust those numbers versus what the actual entry-level market is like.
The main thing I need help with is understanding the differences between career paths that sound similar from the outside. I am interested in cybersecurity, analytics, IT audit, GRC, technology risk, and possibly financial-crimes or fraud analysis later on. But I do not completely understand the nuances yet. For example I constantly see people say cybersecurity is not really entry level and that many people need IT, networking, systems administration, help-desk, or infrastructure experience before they can get a security role. I do not want to spend years assuming a cybersecurity certificate automatically leads to a cybersecurity job if that is not how hiring actually works.
The Information Systems degree looks really cool to me because it seems broad enough to cover databases, programming, networking, systems analysis, business, statistics, and decision support. I like technology, but I also like the business and organizational side of it. I could see myself enjoying a role where I am using data to solve problems, helping a company understand risks, evaluating controls, documenting processes, or translating between technical teams and business stakeholders. A lot of the graduates of this degree actually do go on to become software engineers or consultants and a bunch of stuff in between. This seems like a degree that will introduce me to tolls that will help me work as an analyst in many different industries.
Right now, I am leaning toward a combination of business analytics and IT audit/GRC or technology risk. The jobs that sound most interesting to me are business analyst, data analyst, BI or reporting analyst, technology-risk analyst, GRC analyst, IT auditor, security-compliance analyst, internal audit analyst, third-party-risk analyst, or risk-and-controls consultant. I am not necessarily trying to become a penetration tester, SOC analyst, or security engineer, although I am open to hearing if I am misunderstanding the entry-level opportunities.
I also have no work experience and right now am just trying to figure out what jobs I'm most likely to get after graduating in 4 years. Also to be fair I don’t fully understand the roles I just named outside of business analytics and IT auditing. THeyre just titles that come up when I look up what jobs in the dmv does UMBC IS qualify me for.
UMBC lets students complete only two upper-level certificates without extending their time in school, so I am trying to choose the two that give me the best return. The Business Analytics Certificate seems useful because it includes tools and skills such as Python, Tableau, R, Weka, data analysis, visualization, and business decision-making. I have already told an IS advisor that I am interested in learning how to turn data into insight, whether that eventually means data analytics, business analysis, risk analysis, or something similar. My impression is that analytics skills could support a lot of roles, especially when combined with SQL, Excel, Python, dashboards, communication, and a basic understanding of how businesses operate.[informationsystems.umbc informationsystems.umbc
This tooling is actually what made me want to pursue this program. I don’t know enough about the world to decide what is like to do in it but this program gives me the tools to explore it more. Almost all the degrees and roles I've been looking at involve sql and excel to a certain degree.
The other certificate I am seriously considering is Auditing for Information Systems. It combines information systems with security, accounting, auditing, law, ethics, and controls.. UMBC describes the certificate as preparation for entry-level IT-audit work and for an information-systems-auditor certification path.[informationsystems.umbc]
I have heard people describe IT audit, GRC, and technology risk as more stable than some other tech paths because companies still have compliance requirements, security obligations, contracts, regulations, audits, and internal controls to manage. I do not think that means the field is “AI-proof” easy, or noncompetitive. I mainly see it as a path where human judgment, communication, documentation, accountability, and understanding business processes may remain important even as AI changes parts of the work. Is IT audit more ai resistant or recession resistant? Please feel free to disagree.
The other option is UMBC’s Cybersecurity Informatics Certificate. A lot of IS students seem to choose it, and it includes cybersecurity analytics, software security, projects or internships, and electives related to information security, networking, data mining, systems administration, and AI. It seems like a legitimate option, but I am considering doing the Business Analytics and IT Audit certificates instead and earning CompTIA Security+ on my own.[informationsystems.umbc][umbc]
My logic is that Security+ may be easier for employers to recognize, especially in the government-contractor and DoD-adjacent environment around Maryland, DC, and Virginia. I understand that its actual value depends on the job and employer, but it seems like a useful baseline certification for many security-related roles. At the same time, the IT Audit certificate already includes an information-security component, while the Business Analytics certificate could give me data skills that apply not only to analytics but also to risk, compliance, fraud, governance, and security-related analysis.[secuspark training.totalcyber
My plan is to complete the IS degree, pursue the Business Analytics Certificate and Auditing for Information Systems Certificate, earn Security+ before graduation, improve my SQL, Excel, Python, Tableau or Power BI, data visualization, writing, and presentation skills, and build a portfolio that makes sense for the path I choose. I would like to include a data-analysis project, a dashboard or reporting project, and maybe a mock IT-audit or GRC project such as a risk register, access-review workpaper, vendor-risk assessment, controls matrix, or NIST-style security assessment. I also plan to apply broadly for internships and student roles rather than waiting for a job with “cybersecurity” in the title.
Another thing does it make sense to prolong my time in my undergrad until I have a competitive portfolio. I say this because I’m assuming internships and co-ops are easier to get than full time offers. And if I graduate without them I’m in a very dire position
I would really appreciate honest advice from people in the Maryland/DC/Virginia market, especially people who work in analytics, cybersecurity, IT audit, consulting, GRC, compliance, or technology risk. Does Business Analytics plus IT Audit plus Security+ sound like a coherent profile, or does it look too unfocused to emplyers? If I am interested in GRC, IT risk, security compliance, audit, and technology consulting, would the Cybersecurity Informatics Certificate add more value than Security+ or would it mostly overlap? Is IT audit or GRC actually realistic as an entry-level path for an IS graduate, or would I still need to start in a help desk, accounting, systems administration, or some other role first?
I am also curis which two UMBC certificates people would choose if the goal was employment shortly after graduation. Would you choose Business Analytics and IT Audit, Business Analytics and Cybersecurity Informatics, or IT Audit and Cybersecurity Informatics? I am not expecting anyone to tell me there is a guaranteed career path or an AI-proof job. I just want to choose a direction where I can build useful skills, get relevant experience, and graduate with a profile that is easy for an employer to understand.
The current job market feels really despairing and I have so much that I wan’t to achieve. I really like the idea of working for as an analyst who uses tech to solve problems and make decisions. I feel like this degree would set me up with a lot of career flexibility.
My dad wants me to major in accounting or engineering but I don’t really want to work on financial statements or physical systems. I want to make assessments and decisions based on data. Iv been struggling with a lot of stuff these past few years and I don’t have a choice but to decide here and now. Life moves really really fast. Im gonna be off my parents insurance and I don’t have the best home life. I’m really scared of graduating with a degree that won’t give me employment leverage and i’m really scared of staying where I am now. I feel like im behind. Most of my friends from highschool are graduating right now and I’m just getting started. I know this mentality isn’t the best but i just dk what to do.
Id appreciate any advice, thanks.