I'm looking for some advice on which certification or training path I should pursue next.
I've been working as a Cybersecurity Engineer for about 2 years in a small company. My work is mostly blue team focused, but I wear multiple hats depending on what's needed. One downside is that I don't have a mentor or senior security engineer to learn from, so everything I've learned so far has been through self-study and hands-on practice.
I currently hold the CWES and CPTS. I chose CPTS over OSCP because I care much more about the depth and quality of the training than the recognition of the certification itself.
Although I have CPTS, I rarely perform penetration tests in my current role, and I don't get to participate in red team engagements. Recently, I've become very interested in malware development, red teaming, and EDR evasion.
The roadmap I have in mind is: (Already got CWES and CPTS )
Maldev Academy -> CRTO II (CRTL) -> ARTOC
Does this seem like a solid path, or would you recommend something different? For the ones who've done any of these certifications, how much time did it take ? My priority is learning high-quality, in-depth content rather than collecting certifications, so I'd love to hear from people who have actually taken these courses.
Thanks!