transcribe

ABSOLUTE BEST Way to Get Certified as a Cybersecurity Auditor in 2025!

Boyd Clewis · 14m · transcribed Jul 2026
More from Boyd Clewis Business
𝕏 Share ▶ YouTube 📥 PDF 🤖 .md

Section Insights

# 0:00

Introduction to Cyber Security Careers

How can I get paid to become a certified cyber security professional?

Boyd Clewis introduces the concept of becoming a certified cyber security professional and emphasizes the potential for high salaries in this field, particularly as an information security auditor.

  • Cyber security careers can lead to six-figure salaries.
  • Becoming a certified professional requires dedication and hard work.
  • The role of an information security auditor is highlighted as a lucrative career path.
# 2:58

Understanding Security Policies

What are the key components of a security policy for information security auditors?

The section discusses specific security policy requirements related to passwords and account lockouts, which are essential for auditors to verify compliance with company policies.

  • Security policies include password complexity and account lockout settings.
  • Auditors must understand and verify that company policies are implemented correctly.
  • Compliance with industry standards is crucial for security auditing.
# 5:56

Role of the Information Security Auditor

What does the role of an information security auditor entail?

The auditor tracks compliance issues and ensures that security policies are remediated, using tools and spreadsheets to document findings.

  • Auditors track compliance issues until they are resolved.
  • Remediation is a key responsibility of security auditors.
  • Understanding frameworks like PCI DSS is vital for auditors.
# 8:55

Certification and Skills in Cyber Security

How do I become a certified PCI professional?

To become a certified PCI professional, one must first be hired by a company that will sponsor their certification training, emphasizing the importance of skills over certifications.

  • Skills are more important than certifications in the PCI space.
  • Companies typically sponsor certification training for employees.
  • Real-world experience is crucial for success in cyber security roles.
# 11:53

Transitioning to a Cyber Security Career

How can I transition into a six-figure tech role as a security auditor?

Boyd Clewis invites viewers to apply to his training academy, which offers coaching and mentorship to help individuals gain the necessary skills for high-paying tech jobs.

  • Training programs can help individuals transition into tech roles quickly.
  • Hands-on experience and mentorship are key components of successful training.
  • Building a strong resume with relevant skills is essential for job placement.

Transcript

0:00 hey cyber Heroes Boyd clew is here the six-figure tech career coach and in this video I'm going to teach you guys how to get paid to become a certified cyber security professional I know this might seem crazy but by the end of this video you will be blown away are you ready for this let's go hey cyber Heroes welcome back to my channel if you're new I'm Boyd clewis

0:30 internationally recognized cyber security expert and I help people upgrade their jobs to a six-figure Tech Career if you want to join me on this journey be sure to like this video subscribe to the channel and hit the red bell so that you're notified whenever I drop new content guaranteed to take your career to six figures and beyond all right cyber Heroes before we go into the specific training and certification that I'm talking about I need you to

0:53 understand something this is not just something that you're going to be able to walk into this is going to require work right it's going to require work so I'm going to show you the specific type of role that I'm talking about and then how you can get the training the certification Etc to make this a reality so let's jump over to my computer and take a look at salary.com so we're talking about the role of an information

1:16 security auditor most people don't talk about this again this type of position is in the realm of GRC which is go governance risk and compliance and this specific role has a salary range from a hundred and two thousand to 146 and I personally know people doing 200 000 and above because you know I was one of them anyway so this is the type of role that I'm talking about but I'm going to show you how you can get access to the role

1:43 and what specific area you need to focus on so that you can get training and certification for free okay guys in order to get like the big Tech bag we're not talking about just any kind of information security otter we are talking about a very specialized one and I'm going to give you the details but I think it's important before we go into the details about the specific Niche we understand at a high level what an

2:06 information security auditor is in the first place think of it like this because of different industry standards and government regulations companies have to abide by a certain set of rules for example publicly traded companies meaning companies that you can buy stock in they have to follow a financial right regulation that's called Socks sarbanes Oxley s-o-x not SOC not SOC K we're talking about sarbanes-oxley compliance right as well as companies that work in

2:37 the healthcare field they have to follow in the industry regulation that's called HIPAA right they have to maintain compliance with these regulations and Frameworks or bad things could happen to the company so when we're talking about an information security auditor and information security auditor is a person that verifies controls have been implemented to the specific standard so I'm going to break this down for you real quick so what we have here on my computer right now is a Windows 2020

3:08 member server security policy and so if we look right here the security policy this is specifically around passwords and account lockouts so the policy says enforce password history 10 passwords maximum password age is 90 days minimum passwords age is one day minimum password link is 12 characters password must meet complexity requirements enabled so these are the this where it says settings value these are the specific values that must be implemented

3:39 on a system and if we look at the account lockout policy we see the account lockout duration should be 30 minutes and the account lockout threshold is three invalid attempts meaning if someone enters three invalid passwords that account needs to lock for 30 minutes and then it can reset after 30 minutes right so like as the information security auditor I am going to be the expert on understanding the company policies so that can actually verify the company policy has been

4:10 implemented correctly on the systems now company policies are going to be derived from industry standards like nist CIS as well as other security standards like maybe PCI DSS for example and so like what we would do is is we would take a look at the configuration that's implemented on the server Now understand as a security auditor I don't have the ability to log into this server so the system administrator is going to have to share screens with me or send me a

4:39 screenshot of the system configurations that I need to review if we look at this screenshot here from a Windows Server it's showing the password history being 24 passwords remembers maximum password age is 30 days minimum password age is one day minimum password length is eight characters so as a security auditor we need to compare what has been implemented on the system to what should be implemented based on the security policy and then determine whether or not

5:09 these changes these configuration settings in the system are actually in agreement or compliant with the policy and so I've already done this little audit right here and maybe you can pause this and do the attitude to determine whether or not the system configurations are compliant or not because this is important so if we go down and we look at the added information we understand that the minimum password length of eight characters is not compliant the account lockout threshold of five

5:38 invalid attempts is not compliant why so if we talk about minimum password length of eight characters our security policy says that the minimum password length needs to be 12 characters and because it is not compliant it creates what we call a finding so we would need to notify whoever owns that system or whoever manages the people or team that owns that system then in this case this is Windows Server a it needs to be remediated remediation just means it

6:07 needs to be fixed so as the security auditor we're going to track this finding on a spreadsheet or in a GRC tool until it is fixed and then we're giving additional evidence for us to determine that the fix has actually been done and that is the role of the security auditor so now we need to get into where the training and the big Tech bag comes in let's go hey cyber Heroes right now is a great time to like this

6:33 video subscribe to the channel so that you're notified whenever I drop new content guaranteed to take your career to the next level boom all right now let's get back into it so in terms of being an information security auditor one of the most powerful Frameworks that you can learn is the PCI DSS that is payment card industry data security standard this is an industry regulation for companies that store process or transmit credit card data if they do

7:01 this especially on a large scale they have to comply with the PCI DSS every year they have to certify and maintain compliance every single day you gotta think about it like following your taxes you have to file your taxes every year and you may or may not get audited companies are audited for compliance with the regulation just the way I showed you the audit before and they are audited by an external company generally speaking depending on the size but all

7:30 the companies need to have an internal resource to be able to help them prepare for the Auditors to come so in the situation that I showed you guys earlier with the Windows server that would be me acting in the role of Isa that is an internal security assessor I would do a pre-assessment with the company to find issues that are not compliant to have them fixed before the external Auditors comes up because it actually adds value

7:56 and saves the company money so if we go over to the PCI council's website we're actually going to see one of the most powerful certifications that you can get in terms of the knowledge of the PCI DSS okay guys I'm on the PCS security standards website now here's where things get a little tricky right so I'm going to show you this certification that I'm talking about so we go to training and we go to certifications Isa

8:24 inter Social Security assessor training this is what I was talking about like performing the internal security assessments to help the companies become compliant and you probably wondering how much does this cost no the internal security assessor training is around three thousand dollars I believe I believe it's around three thousand dollars but here's the deal notice how you don't see where you can actually buy it if you don't see where you can buy the training you know why because you

8:51 can't let me explain this the reason why I said this gets a little tricky is because in order to become an Isa you first have to be hired by a company as a PCI professional and then they send you to the training to get certified because the company has to sponsor you so what am I saying most people take the approach of hey man I'm gonna go get this certification so I can go get this job it does not work like that in the

9:21 PCI space what you have to do is get the skill to get the job then the company certifies you I know this is completely foreign to most people because it's like how do I get a job if I don't have a certification it is what I've been telling you guys for years and I'm hoping it's starting to click now guys hoping it's starting to click certification does not equal skill guys you get hired for your skill

9:48 not the certification because there's entirely too many people that have certified but they can't actually do the work in fact you can pay someone overseas to go take and pass these certifications on your behalf for very little money out of pocket which actually devalues the certification while this is so powerful is because guys if you've seen my video where I talk about how I went from 33k to 200 000 it was because of this core skill of

10:18 PCI DSS and it's how I've been helping people make the transition into Tech because I want you to think for a second something that you probably hadn't even imagined say you have no Tech experience right and you are following along at the beginning of this video where we went through a Windows Server audit how many of you have actually configured a Windows Server let me know in the comments if you have not if you have I

10:42 would guarantee that most of you watching this video have never configured a Windows server in your life but you were able to perform that security audit guys you literally performed an audit of a Windows server and so what it comes down to is learning the PCI DSS standard so that you can help companies fix the challenges that they have before the qsa shows up qsa is qualified security assessor they are the third party Auditors that come out in

11:11 audit companies to make sure that they are compliant with the PCI DSS standard because if companies are not compliant they could be fined millions of dollars or even lose the ability to process credit cards altogether which is very very critical and it could you know collapse many businesses if they lost that ability so what is important to do is understand the standard and let me show you where where the standard is all right guys I'm back on my computer right

11:39 now so if we go over to resources we go to document library and then we want to filter this to PCI DSS the current version of PCI DSS is version 321 which will be retired in about 12 months or so somewhere around that version 4.0 is going to be the new version that's coming out that will take precedent but right now companies can still certify with version 3.2.1 you can download this standard and take a look at the requirements

12:09 understand there's more than 200 plus sub requirements but having an understanding of these security requirements will help you take your career to the next level because what you can do is update your LinkedIn resume update your digital resume and look for jobs based on the skill of PCI DSS because there are tons of them okay cyber Heroes just to reiterate the way this goes is learn the skill right be able to speak to it get the job

12:39 become certified that is the way that it should go and you may be wondering like okay okay I I see what you're saying Boyd how do I even make this happen I'm so glad that you asked I would love to be able to teach you this skill that will help you transition into one of these six-figure Tech roles as a security auditor I invite you to apply to the Baxter Lewis Training Academy you can go to boydcoolers.com forward slash

13:03 GRC to check out our case studies of how we've helped hundreds of people just like you upgrade their jobs to six-figure Tech careers in as little as 90 days with the coaching mentorship internship the success advisors to walk with you through this program while you learn these skills and get Hands-On application so that you can get the confidence and the abilities to go land a job and you may be asking okay okay so I'm watching this guy on YouTube what

13:32 makes him even qualified to be able to teach me this skill so let me show you so first of all guys remember industry recognized cyber security expert I have been qsa security consultant for some of the largest companies in the world and I regularly speak at the PCI Community meetings in North America and Europe you can check me out here in fact if you want to meet me in Portland Oregon at the PCI community meeting or in Dublin

13:57 Ireland this year come sue your man and like this is what I have been doing for the past decade guys so I would love to be able to share my expertise with you to help you overcome the challenges and things when it comes to Growing your career and taking it to the next level so remember you can go to void clues.com forward slash GRC to apply I would love to work with you to help you take your

14:20 career to the next level without needing any college degrees certifications or skills like hacking or coding we've been doing this for years and I'm sure that we can help you if you're willing to put in the work well guys if you haven't already like this video subscribe to the channel so that you're notified whenever I drop new content guaranteed to take your career to six figures and Beyond and I will see you on the next one peace

14:48 foreign

Summary

Boyd Clewis, a six-figure tech career coach, outlines how to become a certified cybersecurity professional, specifically focusing on the role of an information security auditor. He emphasizes the importance of gaining practical skills and knowledge, particularly in compliance frameworks like PCI DSS, rather than solely relying on certifications to secure a job.

- Information security auditors verify that companies comply with industry regulations and standards, such as Sarbanes-Oxley (SOX) and HIPAA.
- The salary range for information security auditors is between $102,000 and $146,000, with potential earnings exceeding $200,000.
- The role involves assessing system configurations against established security policies and documenting findings for remediation.
- Gaining expertise in PCI DSS is crucial, as it is a key compliance standard for companies handling credit card data.
- To become a certified Internal Security Assessor (ISA), individuals must first be employed by a company that will sponsor their training, which costs around $3,000.
- Boyd stresses that practical skills are more valuable than certifications, as many certified individuals lack the necessary competencies.
- He invites viewers to apply for his training program, which offers mentorship and hands-on experience to help transition into six-figure tech roles.
- Boyd's experience includes working with major companies and speaking at industry events, reinforcing his credibility as a coach.

Questions Answered

How can I get paid to become a certified cyber security professional?

Boyd Clewis introduces the concept of becoming a certified cyber security professional and emphasizes the potential for high salaries in this field, particularly as an information security auditor.

What are the key components of a security policy for information security auditors?

The section discusses specific security policy requirements related to passwords and account lockouts, which are essential for auditors to verify compliance with company policies.

What does the role of an information security auditor entail?

The auditor tracks compliance issues and ensures that security policies are remediated, using tools and spreadsheets to document findings.

How do I become a certified PCI professional?

To become a certified PCI professional, one must first be hired by a company that will sponsor their certification training, emphasizing the importance of skills over certifications.

How can I transition into a six-figure tech role as a security auditor?

Boyd Clewis invites viewers to apply to his training academy, which offers coaching and mentorship to help individuals gain the necessary skills for high-paying tech jobs.

© transcribe · For agents Built with care and craft by Gokul Rajaram