0. Do not pursue certifications at all.
1. Learn to code. C + Python is a great choice, to start with (or C + Ruby).
2. Start with application security, because it's the easiest place to get your feet wet.
3. Work through The Web Application Hacker's Handbook (don't just read it).
4. Find bug bounties in as many programs on BugCrowd or HackerOne as you can. Extra resume points (and money!) for bug bounties in Google, Facebook etc.
5. Join a reputable security consultancy (NCC Group, Optiv, Bishop Fox, etc.) and mature your skills.
6. Decide how you'd like to specialize.