And despite this, most companies are trying to get senior software developers for the AppSec programs but can't because they don't want to pay senior software developer salaries, or even software developer salaries. So the positions remain open, month after month, sometimes year after year.
I've been told several times this is because AppSec is considered by higher management to be mostly a clerical type position or at best, Application Support. Which would be fine if that were the level of experience and bundle of skills they were trying to hire, but it's not. What makes things even more difficult is that many companies have a policy of only hiring citizens and permanent residents for these positions but have outsource rates floating in their heads.
If you want to have an AppSec group populated with people who can explain (and often argue) security vulnerabilities in the code of others, you're going to have to pay for someone with enough experience to do so credibly (or you'll lose buy-in from developers) and knowledgably (so you're not wasting developer time with false positives).