ALL of cybersecurity is just operating and configuring a platform, whether it is Qualys or Snyk or Wiz or something else. "cyber" people are basically TOOL MONKEYS, and if SRE people can handle operating and configuring kubernetes - they sure as hell are capable of operating and configuring Qualys and Snyk and Wyz platforms.
Pentest is the same, I have not met any inhouse dedicated pentest folks, it is always third party contractor hired as needed for a short period of time. All inhouse fulltime cyber engineers are dedicated to blue team operations, rather than red team operations.