As a Blue team member who works in the medical field, I must agree, that demand is high. We hire a firm to do Red team, but we do have our internal folks too, along with us Blue team folks who learn Red team stuff. We worked with a major security firm and together we accidentally created Purple team.
We had the Red team come in and while pentesting share his screen with us all. Another Red team member explained what he was doing and after an attack was launched and we would see if our tools detected the activity. If they didn't, we went out to find out why. This was huge. It showed us where we needed to tune some things and where we needed newer and/or different tools.
This isn't the only way we get pen tested. They do their annual "regular" pentest. The Purple team thing was awesome though. We learned a ton. Since I happen to own most of our tools and am secondary on the ones I don't own, I have learned a tremendous amount and I've been in IT for 20 years.