That's a story that people like to tell to justify bug bounty programs, but it strikes me as very unlikely that some random pentester / white-hat hacker would have access to communication with malware producers.
Black-hat hackers seem entirely unreasonable to deal with, you'd have to manage some sort of escrow payment (because neither party trusts the other) probably through cryptocurrency, and then deal with laundering the money, et cetera.
Perhaps one could as you theorize, go to some private company, but it'd have to be at least somewhat approved by the white-hat hacker's own government lest they risk legal trouble, and I'm still dubious that the company would be all that willing to pay for some "freelance hacker's" supposed vuln.
The logistics just don't make sense.