Problem is you can't gain the experience without a CISSP, for the most part. You have to get lucky that you're either promoted or transferred to a security position. That needs to change at the entry level, so these folks can get the relavent experience. Then apply to take the ISC2 or CISSP....One does not necessarily have to obtain an MSCA or MCSE just to get a foot in the door. You are not applying for a sysadmin gig when starting out. At this point, A+, Net+, and ITIL are seen as the gatekeepers.