(We've never done work with NASDAQ).
It is extraordinarily rare for talented security firms (which tend to be --- no, wait, are invariably boutique operations) to get true site-wide discover- audit- recommend-
retest- repeat-til-fixed projects.
The closest approximation that boutique firms get regularly are "sitewide pentests", which compromise the objective you're talking about by (a) timeboxing the project (and particularly the earlier discovery phase of the project), (b) deliberately hiding information from the team (often in the name of "judging what attackers would find in the real world") and (c) if retesting is part of the project, its one cycle. While large companies use sitewide pentests as their "once a year do the whole network" project, the reality is that these projects are designed first to prove that it's possible to pop the network (it always is), second to provide a triaged list of "most glaring" security flaws, and only lastly as a true survey of all the weaknesses on the network.
This makes sense, because the true survey would cost 5-10x more, involve weeks (not days) of discovery, doc review, and staff interviews, and take many months to run start-to-finish.
There's a lot of value in sitewide pentests (I think past a certain size every company should do them every year), but a lot of people have unrealistic expectations about what they can really accomplish. For most companies, if you're going to need to catch things like "one unpatched Win2k3 server in an obscure application cluster from a company you bought 5 years ago", you're going to have to match the external consultant pentest with a very focused very diligent very well-designed internal security effort designed from the outset understanding the limitations of pentesting projects.
My perception is that larger security firms do in fact get the all-singing all-dancing sitewide audit/fix projects, but those companies often are just feeding at the trough, sending people with no real talent for the work to bill lots of hours. It's also, frankly, hard to get talented people excited about spending months reviewing firewall rules.