As a software test engineer, we do external audits like this, but I wonder: Documented or "known" vulnerabilities are not worth testing until there are systems in place that expect to cover them.
It seems that all vulnerabilities that are not intentionally addressed should be considered dangerous. If they are penetration tested but vulnerability is unknown, the best you could hope for is "Not vulnerable for unknown reasons" which is just as bad as vulnerable in my perspective.
With some admitted trepidation, I assert that all software should be tested this way, with expected behavior being a primary dependency.
Edit: hiring outside penetration testers is still totally valid and desirable, since development and testing are two totally different domains. I'm only pondering methodology.