Mirin4rmfar
Superstar
Since I am in the GRC game, let me drop some jewels on you breh :
- PCI is cool, I don't come across it as often as I thought. Choose your certification carefully, some of them are linked directly to your current role. Make sure whatever you get doesn't require you to be working for an ASV.
- ISO 27001 is VERY popular with international companies. I got a few companies certified (I'm in Canada)
- SOC2 is the equivalent of ISO 27001 in the States. I'm going through training from the AICPA.
- CMMC compliance is coming in strong as a Government requirement.
With all the certs you got already, adding PCI and one of either ISO or SOC2 will be . Be ready to get challenged on the regular, some devils hate seeing overly certified guys .
Base on what the coo mentioned, I will be doing tons of soc2 then the rest is pci, HIPPA etc.
That's the only way I can properly sleep well at night ..cert up so the next opportunity is easier to get in case a company give you an L. They can hate all they want. Getting my CISA/CRISC is the biggest reason why they hired me. I will be on the road 50 percent of the time but once I understand everything, I am bouncing to my next role.
No more waking up middle in the night since someones network is down lol.