thinQmaster Virtual testing partner Adaptive practice exams that find your weak spots and drill them. Every answer explained. From $69

thinQmaster

Find your exam

Five questions free, before you decide.

Step 1 · choose a vendor

In one of our camps? Your practice exams come with the tuition — they are on your study page already.

thinQcompass

Tell us where you are standing and which way you want to go. We will lay out which certifications to take, in what order, and how long each one is likely to take you — including the ones we do not teach.

Plan my direction
Have a job in mind? Paste the details and we will read them

Paste the details of the position or offer — the requirements section is the part that matters. We will pull out the job title, the certifications it asks for, the experience and the pay, show you what we matched, and build the route from there.

Security Manager / CISO

Owning security for the organisation. Risk decisions, budget, audits, board conversations, and being accountable when something goes wrong.

$175,140Median pay
12 moYour horizon
8 hrsPer week
3Steps in range

Pay is the US Bureau of Labor Statistics median for Computer and Information Systems Managers, May 2025 — the occupation this job is counted inside, which is usually broader than the job title itself. Counted with all IT managers. A CISO at a large firm earns well above this median and a security manager at a small one well below; the single figure hides a very wide spread. Study times are our own estimates for someone working 8 hours a week, and they are ranges for a reason.

ISC2 CISSP: ISC2 wants five years of paid work across two domains. You may sit and pass the exam first and hold Associate of ISC2 status until you have the years.
Most postings for Security Manager / CISO name a bachelor's degree. Plenty of people hold this job without one, and certifications plus demonstrable experience are how they got there - but expect the résumé screen to be the hard part, not the interview.
Security Manager / CISO is not usually a first job. The realistic route is security engineering or GRC, then a lead role. The credentials below are necessary and nowhere near sufficient - this job is won on judgement and track record. The plan below is still the right study order for getting there - it is the timeline to the title that is longer than the timeline to the certifications.
2 further steps sit past your 12-month horizon. They are shown so you can see the whole route; they are not lost, only later.

What are you aiming to earn?

$175,000
$62,000 $176,000

Security Manager / CISO reaches this. Its median is $175,140.

Your sequence

In order. Each step assumes the one above it.
Scroll the steps — the marker follows  
$129,180 · Information Security Analysts $175,140 · Computer and Information Systems Managers

Both ends are US Bureau of Labor Statistics medians, May 2025. Everything between them is a straight line we drew, not data: nobody publishes pay per certification, and real pay moves when you change job, not when you pass an exam.

  1. 1

    CompTIA Security+

    1.8-2.8 months · from month 1

    The baseline security credential, and DoD 8140 approved - which is what unlocks federal and contractor roles.

    ~$138,372 modelled Associate We teach this See dates →
    Other ways to take this step
    • Cisco CCST Cybersecurity — if you want to show security intent before you are ready to sit Security+
  2. 2

    CompTIA CySA+

    2.8-3.9 months · from month 3

    Detection and response. The natural next step after Security+ for anyone heading to a SOC.

    ~$147,564 modelled Professional We teach this See dates →
    Other ways to take this step
    • Cisco CyberOps Associate — the Cisco equivalent - do one of these, never both
    • ISC2 SSCP — if you are heading toward CISSP eventually and want the ISC2 track early
    • EC-Council ECIH — if incident response specifically is the part of the job you want
  3. 3

    ISC2 CISSP

    4.4-6.7 months · from month 7

    The management-track security credential. Needs five years of paid experience to be fully certified - you can pass first and associate until you have it.

    ~$156,756 modelled Expert We teach this See dates →

    Experience requirement. ISC2 wants five years of paid work across two domains. You may sit and pass the exam first and hold Associate of ISC2 status until you have the years.

Past your 12-month horizon
  1. 4

    ISACA CRISC

    2.8-3.9 months · from month 14

    Risk, in the language executives and auditors use.

    ~$165,948 modelled Professional We teach this See dates →

    Experience requirement. Three years in risk management. Pass first, certify later, is permitted.

  2. 5

    ISACA CISM

    3.2-5.1 months · from month 18

    Security management rather than security engineering. Needs five years experience.

    ~$175,140 modelled Expert We teach this See dates →

    On the model, this is the step that reaches your $175,000 goal.

    Experience requirement. ISACA wants five years in information security management. You can pass first and certify once the experience is documented.

Change your answers

Nothing is saved and no account is needed. Your answers live in the page address.

What interests you?

Pick as many as apply. If you are not sure, pick the one you would read about on a Saturday.

Where you are now

Both of these change the plan. Experience especially — it decides what we skip and how fast we think you will move.

How much time you have

Be honest rather than optimistic. A plan built on hours you will not find is a plan you abandon in week five.

$62,000 $175,000 $176,000

Anything you already hold

Tick these and we will not sell you a course you do not need.

I already hold some certifications

Free, and it will tell you about certifications we do not sell. If the honest answer is that you need something we do not teach, the plan says so.