While I do agree this is important in various roles in the security realm, there are also many jobs where this doesn't really add value. A lot of work is about implementing things like MFA, role-based-access etc where knowledge of the platform used (e.g. Microsoft) and internal processes are more important. After all, most companies already fail at the 'fix the obvious' stage, it's not necessary to go looking for clever ways in when there are many doors left open.
Just to elaborate: A lot of discussions go like this. A pentest or random scan finds obvious issue. Ticket is raised to the security team. They go like "WTF why do we still have Windows 95?? Kill it.". Then their boss goes like "Sorry, Bill the manufacturing VP lobbied with the CEO, we have to leave that one alone". Of course when it actually gets hacked, Bill is nowhere to be found. This is why internal influencing skills are so important in real everyday security jobs.
Of course in the pentesting role this kind of thinking is absolutely necessary. However even there the kind of training given right now is too much in the realm of 'scriptkiddie'ism. Hacking is about inventing and true mastery of technology, not about using the tools everyone uses. Being able to run metasploit and wireshark does not make one a hacker. By doing this, pentesters test for yesterday's hacks, not tomorrow's.