I assume part of the reason is that certs are expensive and not well respected, so the only reason you would get them is if you had no other options.
I assume part of the reason is that certs are expensive and not well respected, so the only reason you would get them is if you had no other options.
I should also clarify, I only put certs that matter (why put an Azure cert on a resume submission to an AWS shop) and certs that are recent (I have 20 years on my resume, why would i put my CCNA on there). I think a large number of irrelevant certs would be a negative signal. I think a large number of relevant certs AND job history to back them up would be a super strong signal.
That being said, 20+ CompTIA cents isn’t going to move the needle for me.
I say all that to say “it depends on the cert”
I don’t know what jobs you’re hiring for, if any, I simply don’t see how more data is a negative signal.
I think that’s silly.
I disagree with the entirety of your reply, except for the CEH zinger ;)
The CISSP is a risk management cert that's sometimes oversold as an infosec cert. It's been quite useful to me in dealing with the (Fortune 1000 mostly) bureaucracies that take Red Team and pen test findings and turn them into remediations or risk acceptances.
The OSCP is a technical cert that's oversold in a different way: because the test is fairly difficult, lots of people assume it's an advanced cert. It's a beginner cert (and Offensive Security has several more you can take after it). What it does prove is that you probably have the right mindset to be a penetration tester (which is not necessarily the same mindset you need for Red Teaming, i.e., unannounced adversarial simulation).
tl;dr: I don't think any cert is bad as long as everybody understands what it's for. But I'm one of those people who collects them (at employer expense) as a way to structure my learning, and then never renews them.
It's kind of a stupid response, especially considering that the same people would most likely view 10+ certs on your CV as a positive if your name is western-sounding...
With the popular exams, it is mind-numbingly fast. Think days to weeks. Crowdsourcing / MTurking the question banks is depressingly effective if you sweated over nearly a thousand question bank items for a few months with a few other expensive experts.
Labs in the exams are a way to blunt this, but I think the exam dump industry has probably come up with a way to defeat labs as well by now, because the labs run a fixed set of scenarios with variations in parameters but not the general gist. It's better, but still hackable.
What I've come up with requires discipline by a team documenting the issues they've fixed in the past, but it is so far 100% foolproof. Pick a random relatively self-contained issue your team fixed in the past; this is the most critical step governing the quality of this technique's results. Reproduce the issue in a scratch environment.
Sit down the candidate in front of a workstation set up to their preferences you gathered in advance, with all the tooling they prefer, simplifying your superfluous environment specifics where possible (like logging them into various accounts ahead of time). Set their expectations ahead of time that they will be team / pair troubleshooting for half an hour, that you aren't evaluating whether they find the root cause or not, you're evaluating how well they work with others troubleshooting an issue in some system/language/etc. they claim they are a domain expert in. Dive in.
Without fail, the ones who exam dumped their way to a certification will thrash about. Hard. Most common is they will not know where to even start, deer-in-the-headlights. Even telling the candidate straight out where to start, by using your 20/20 hindsight and artificially picking a starting point 1-2 steps away from the root cause still does not unlock them; jumping to a known good starting point is useful for the experienced candidates who freeze under interview pressure, as they usually unfreeze when given such a big head start from your IRL issue that you ran into for the first time.
You can often get a good gauge of how much and how deeply the candidate worked with the stack they claim competency in by how they navigate around, ask questions, probe for error messages, etc.
How does the quality and value of, say, CompTIA, Cisco, AWS, OSCP, K8s, Linux+ and other certs compare with each other?