Quite a few comments here are mentioning that certs are not useful for offensive security. That's true, but offensive security =/= InfoSec...
When you come on Hacker News and see submissions full of comments about the technical details of exploiting some hot new critical remote code execution vulnerability, or read a hacker's blog walking through how they discovered security holes in some websites, or see an article by some cybersecurity company detailing how they tracked down some crime ring or nation-state backed hacking group, please be aware that 1) these are amazing things, and 2) they are not InfoSec. Information security is a management field and is mostly focused on developing top-down security strategies for organisations to implement, measure compliance with, and refine over time. It is related to, but also very different from offensive security. Relevant HN submissions would be high-profile cyber security incidents and updates on laws/regulations on computer use and data privacy.
You mentioned Sec+. It has gained popularity in the past decade and is now considered an entry-level requirement for many IT contracting jobs, especially government ones, and not even ones that are really security-related. If you don't usually get down in the weeds on computer security topics, then a Sec+ is a useful way to get broad high-level exposure. Another way to look at it this is that a Sec+ is for people who do not have a lot of pre-existing skills in computer security. It's used by employers to filter out employees who probably cannot be trusted with anything security-related in IT. Imagine your employer is thinking of having you sponsored for a security clearance - if you cannot pass a Sec+, than you're probably not cut to have a clearance in the first place. Realize that practically all of these organisations have to annual security awareness training (SAT) to their employees, but by making Sec+ a requirement, they now have a way cut out everyone who would have just slept through the SAT without really internalizing it.
We've established that the true purpose of Sec+ is for screening entry-level IT positions. The CISSP is similar, but for management-level positions. Primarily, it's for middle-managers who want to prove to HR that they are worthy of being chosen for information security roles study the CISSP. Contrary to what people say on the internet, the CISSP is actually very similar to the Sec+, but with more depth on information security management practices. The enhanced focus on information security management practices is because managers with a CISSP are expected to run information security-related projects and programs for the organisation.
Personally, I made a goal for myself at a young age to get the CISSP simply because I saw it was being hyped online. I didn't even do enough research to understand that years of experience was a requirement. I passed it a year before I even started an IT career. It's very doable depending on how much of a computer geek you are. I let it lapse since I was still working in restaurants and had no IT experience, but a decade later, I went for it again because 1) my employer paid for it, and 2) I consult to customers who are CISSPs.
It's important to research what a cert requires of you in order to maintain it. Both Sec+ and the CISSP require you to accrue a certain number of credit-hours every 3 or so years. There are also member dues. If these aren't too much of a hassle for you, then I recommend certs that are relevant to the environments that you work it. In my case, I got a CISSP because I work with CISSPs. I'd consider other certs if the people I work with had them too. I may not be an expert like what the commenters here are decrying as reasons not to pursue certs, but at least I can show a basic level of competence out of respect for the people who I work with.