Given a reasonably competent development team, you can usually make a first pass and find quite a number of low-hanging fruit security issues. Everyone makes mistakes, especially when under pressure to get a product out. Once those are gone you can use fuzzing and/or static analysis type techniques to find another set, but after that you get to the point where the bugs start getting quite obscure and require a fairly deep knowledge of how the system works so you can start stringing multiple problems together to get to a real security issue.
Of course this can be offset somewhat by the fact that software is usually a moving target, so if you're security testing a live, active codebase the developers are likely introducing new issues all the time, though hopefully at a reduced rate as they learn from their previous errors.
I would make this your tagline in some way -
"I will find vulnerabilities. If I don't, I will become a vulnerability to my own body and attack myself until I do!"
http://en.wikipedia.org/wiki/Yakov_Smirnoff - referred to as a Russian Reversal
Ok, learned something completely wasn't aware of before.
But, no, no intent to make that kind of joke.