True,
IF software were actually built like bridges, as in actually engineered, effects calculated, simulated, and tested ahead of time, according to required standards, only by people who are trained. licensed, and insured to do such work, and with the expectation that it will be built once (not updated with patches on an ad-hoc basis). Oh yes, and all subject to strong liability.
Instead we have project who care only about shipping their latest favorite features yesterday to meet the over-promised new capabilities to the new client/market, and figure any problems will get caught with the update cycle, and the coders scrambling to ship the first thing that'll compile and pass the test screens, with QA being a minimally funded function as yet another cost center to be minimized... Oh, and all liability for failure is disclaimed or fobbed off on the consumer for their failure to maintain proper opsec. Oh, and in many cases, the blame is put squarely on anyone who finds such a fault instead of on the builder (e.g., when the governor recently tried to jail a journalist who found an egregious flaw in a state website).
So, yeah, it SHOULD never be the case if there were proper development and proper QA. But it hasn't happened in a half century of large commercial software. So, we do really need pentesters. They're just delayed QA after all.