"Blue team" certifications

I have the CEH and CISSP. The CEH meets a US government requirement and so does the CISSP. Having been through many job interviews, the non-infosec interviewers/HR people see the words ‘certified ethical hacker’ as impressive, regardless of the meat of the cert. Having said that, CEH is not worthless. It has alot of basic infosec concepts that will inform and enrich, especially anyone new to the industry. CISSP was the hardest exam I’ve ever taken. Mainly as it is not a technical exam. It is a lot of ‘what is the best method to …’ where there are several ‘right’ answers to choose from. It is testing your ability to build and manage a security program for an organization (maybe the ultimate blue team manager?). As a sec engineer I would say that understanding CCNA, window admin, linux admin, sec analysis (e.g. SIEM skills) are topics that are important, as well as any coding training. So training/certs that give you those will get you what you need. Working toward a CISSP if you plan to be an exec some day (or work in anything DOD related).

To a larger point I really warn against the ‘cert vs experience’ or the ‘which cert is better’ arguments. Certs are valid and useful. Experience is valuable. Which cert is ‘worth it’ depends entirely on the individual. If you have the OSCP, but have never looked at any other aspect of infosec, you migh gain some understanding with the CEH as it is more broad and less deep. If you can already perform Pen tests, then the OSCP is only useful to put on resume/cv. If you need to engineer security automation with red hat ansible, then all those certs are “worthless”. I would exam what path in info sec you want to take (even more specific that blue vs red) and look at what training you lack, then go from there. And as others have mentioned, when your employer offers to pay for a cert, just get it. It won’t hurt.

Good Luck!