Some are hired by companies to find vulnerabilities inside their own company’s systems. They then report those problems so that they can get fixed before a malicious hacker hits it.
Some individuals are finding problems in other people’s systems. They then alert the owner to the problem so that it gets fixed before a malicious person hits it. There are even companies paying these people for every security hole they can manage to find.
In both of these cases, the person is either hired to do something or is engaging in behavior that is generally considered to be good by these companies.
As for companies going after other companies (e.g. like how Google will seek out security flaws with Apple or Microsoft) or governments going after anyone, I guess that comes down to a case-by-case basis. What is the motivation? What is actually being done? What is the expected, desirable, and actual outcome?