In general I found that customers that demanded certifications were not expecting our consultants to do much thinking, they really just wanted box checkers. I didn't quite understand this until after a few years of hiring folks that were hell-bent on stacking certs...they tended to be box checkers. So, intentional or otherwise, it ultimately made sense.
I find that the education associated with most (not all) certs to be sub-par and not particularly applicable, and it tends to stratify the thinking around how you educate yourself in a career that is at least as much based on vocational/practical knowledge as it is academic. Right now I'm working as part of an infosec org that is >>1000 full time employees and industry certs are a non-factor, the company generally doesn't invest in them unless they somehow directly align with your role and almost nobody that I work with advertises that they have any.
So, in short, I'm closer to anti-certification than anything. That said, don't be religious about it. If that's what the offerings in your area or industry of interest require, do it.
Is GRC security? Not exactly, but if you can’t demonstrate security, no one knows if you have security or not. GRC is the ability to quantify/qualify security.
For true security, as in secure-by-design, etc, you need subject matter experts in that field. Since there is no security knowledge qualifying body for (most) platforms, the credentials don’t really matter much. But for GRC, they are essential.
The question is also difficult to answer because there is no one thing that is security. You can manage vulnerabilities or provide incident response, both security topics but with wildly different skill requirements, for example.
Security engineering, security management, security testing, security reporting, etc, etc. All very different things.
Overall I find these certs to be a waste of time and money, and when hiring candidates I usually filter out those who have every ISC2 cert under the sun.
In fact I tend to dismiss CVs for non entry jobs that have certificates listed at all.
If you have 10+ years of experience I don’t care about your “education” if those 10 years can’t speak for themselves you’re probably not the candidate I’m looking for.
Listed? I guess every employer has their own little biases.
Infosec is very much "learn by do", because technology and this corner of it specifically moves too fast for certificate processes