Earlier quoted context omitted.
I didn't really find it that difficult to move from security consulting/research/code audits => dev/researcher at security vendors => machine learning engineer. So I don't know how we decide whose anecdote wins here :p
Simple. If you value your career as a dev, you won't become a pentester. :) There's no upside except intellectually. Being a dev pays more and gives you more options going forward. That's a harsh way to frame it, but it's also accurate. (I'm speaking from experience FWIW.) In other words, you could have become an ML engineer anyway. No reason to risk it by becoming a pentester.
I wouldn't really recommend being a pentester either, but there is plenty of need for people who understand security and can code to write software.
It seems like you're having a tough time, and maybe ageism is a factor here, but none of what you're saying really meshes with my experience.