Earlier quoted context omitted.
I used to do interviews for pentesters at an old job, and I was suprised as well. I think it's because CyberSecurity is relatively new, so companies have no idea how to hire for it, and end up hiring whoever can talk the best. I interviewed a lot of people with titles like "Senior Cybersecurity Engineer" who had no security knowledge beyond how to run an automated scan against an IP range, and put the findings it pri…
That's also the kind of report that management would like to hear instead of the real report, which should say things like "every single person on teams X-Z should use a password manager and 2-FA for everything they access both in business and in private". Security is a bother at best, and disruptive at worst. It's a tough sell, and it's so much easier to point at some badly configured network devices.
Yep, the devs where I work actually went to my manager and said that me reporting security findings that need to be remediated is messing up their timeline, so they wanted all testing to be put on hold until the app was already in production. Luckily my manager pushed back and said that if they don't want their timeline messed up by constantly having to remediate findings, they should stop including basic vulnerabilities in their code.