Mirin4rmfar
Superstar
Since I am in the GRC game, let me drop some jewels on you breh:
- PCI is cool, I don't come across it as often as I thought. Choose your certification carefully, some of them are linked directly to your current role. Make sure whatever you get doesn't require you to be working for an ASV.
- ISO 27001 is VERY popular with international companies. I got a few companies certified (I'm in Canada)
- SOC2 is the equivalent of ISO 27001 in the States. I'm going through training from the AICPA.
- CMMC compliance is coming in strong as a Government requirement.
With all the certs you got already, adding PCI and one of either ISO or SOC2 will be. Be ready to get challenged on the regular, some devils hate seeing overly certified guys
.
Base on what the coo mentioned, I will be doing tons of soc2 then the rest is pci, HIPPA etc.
That's the only way I can properly sleep well at night

No more waking up middle in the night since someones network is down lol.