Earlier quoted context omitted.
Consequences are happening. People just don't see them because this happens well above the IC pay grade and takes some time to percolate down and no one wants to publicly announce you shitcanned 5-10 people in middle management and security leadership because you enter thorny employee litigation territory. That said, I agree with the author about mismatched expectations, though I can safely say that $500k year is VER…
> I don't care that you feel restricted Yeah well, this is why we don't like security engineers. You absolutely should care that the policies you push for are making workers feel restricted. For your job to even exist, engineers must be able to produce just remember that.
Ideally, Security Ownership should be taken up by the Application/Dev team with an open understanding that heads roll if you messed up ("ownership"), and a security team and platform team exists to help consult and implement security and deployment.
I guess they call philosophy "DevSecOps" or "Shift-Left" in the Gartner world.
That said, a lot of "security" practices are pure BS and security theatre.