I want to be a consultant for web apps security testing.

Why would anybody need a consultant if they already have some opensource tool to do application vulnerability tests ?

Any points ?