Why I'm pursuing the CISA
I've spent nine years as a systems and network engineer at an MSP, supporting more than fifty client environments. I've earned the A+, Network+, Security+, a WatchGuard certification, and the CWNA. I know how networks break, because I've been the one paged at 2 a.m. when they do.
And I'm good at it. But somewhere along the way, the work I kept gravitating toward wasn't the break-fix — it was the questions underneath it. Are the firewall rules actually doing what the policy says? If someone asked me to prove this environment is secure, could I? What would I find if I went looking?
I got my answer when I did a NIST-aligned security assessment of a WatchGuard firewall deployment: documented findings, risk ratings, remediation recommendations. It was the most satisfying project I'd done in years. Methodical. Evidence-based. No 2 a.m. pages.
That's the job I want. Structured, predictable, primarily remote work in GRC or IT audit — ideally with a bank or credit union, where the controls actually matter and somebody reads the report.
The plan
I'm studying for the CISA on a 13-week plan, about five to seven hours a week around a full-time job and a family of five. Free resources first, practice questions on a schedule, exam targeted for December 2026. My strongest domains are 4 and 5 — no surprise after nine years in the trenches — and governance (Domain 2) is where I have the most ground to gain.
I'll be writing about the journey here: what's actually hard about the material, where engineer instincts help, and where they get in the way.
If you're a hiring manager in GRC or audit and you made it this far — let's talk.