n1. Solid external and internal network penetration testing experience—this is the primary requirement.
n2. Hands-on manual exploitation experience, not just vulnerability scanning or tool operation.
n3. Experience with writing client-ready reports and delivering engagements independently.
n4. A recognized hands-on pentesting certification—OSCP, OSCE, GPEN, CRTO, or equivalent.
n5. Strong communication skills and the ability to competently discuss findings with clients.
n6. Senior-level resources are preferred; however, strong mid-level candidates can also be considered if they have genuine hands-on experience with the engagement types listed above.
n7. Web application testing is still relevant, but it is secondary to external/internal network penetration testing for this requirement.