Background: I have 11 years of experience working with OT systems (BAS, ICS) as a mechanical engineer. I have Sec+, CISSP, and my P.E. certifications.
I know market sucks now and I'm fortunate to have a decent job at the moment. The issue is there's no more room for me to move up and the supervisor roles are basically for certain people within the org. I'm trying to pivot more into the security role and move up.
Would moving to a GRC role be logical? I've considered controls engineer but right now my only choice is 1.5 hrs away. My current role deals with System Administrator tasks, security documentation to make sure we adhere to NIST 800-53, NIST 800-82, FISMA, and FIPS.
Also, would CGRC be beneficial? I know CRISC is more known but I dont know if I want to pay another $100+ annual maintenance fee on top of CompTIA and ISC2.