If you want to get into IT sec, dont bother with certs first. Change your mindset and be security-centric. Many IT guys from infra/systems/networks/apps go for certs and fail terribly at the interview sessions.
Im in the security field for 5 years now, and have interviewed many guys wanting to join, so maybe these tips will be able to help you.
- Practice. Security exists in all IT related pillars. If you are a network engineer now, blocking unused ports is a security action. Analyzing traffic packet is a investigation. You are doing it daily, without you knowing it. For systems, if you can harden your machine, you can do security. Designing an app and running the code against known vulnerabilities, that's security too. By informing your interviewer that you are capable of doing these, you will definitely net a entry job in security.
- Stepping stone. Watch the job market. sometimes when a new tender is awarded, the vendor will be in a rush to hire entry level guys. Take the chance and join them, even though the pay is crap and hours are erratic. The job will probably suck too, as you will be basically picking up calls and doing very low level operator tasks. However, if you can tough it out, the weak will leave and you will assume more roles, and hence learn the more "advanced" roles in security, such as malware analyzing, traffic investigation and ruleset crafting.
You need to understand how security works. It's not like military where you shoot me, I shoot you back. In most cases, you only defend and mitigate. It's like someone slapping you, but you can only block or dodge. It takes a strong minded person to do that.
Good luck