📋 IT / Security Audit
Cybersecurity career path
Assess control effectiveness and provide assurance to boards and regulators.
Typical roles
- IT Auditor
- Security Assessor
- QSA
Suggested certifications, by phase
Foundation
- CC ISC2 Certified in Cybersecurity
- Security+ CompTIA Security+
Core
- PECB 27001LA PECB ISO/IEC 27001 Lead Auditor
- GCCC GIAC Critical Controls Certification
- CTPRP Shared Assessment Certified Third-Party Risk Professional
Advanced
- CISA ISACA Certified Information Systems Auditor
- IIA CIA The Institute of Internal Auditors Certified Internal Auditor
- PCI QSA PCI Qualified Security Assessor
Mastery
- AAIA ISACA Advanced in AI Audit
- CRISC ISACA Certified in Risk and Information Systems Control
A suggestion, not a set of prerequisites — one or two certifications per phase is plenty.