This could be because product development is much more quantifiable, while infosec is not. This means the grift can continue for a long time, before an actual ransomware incident happens and the team gets fired. Afterall many of the recent companies that were hacked had contracts with cyber defense firms, but they were just too busy posting memes on social media.
Side note: you should read my other comment on this thread.
Side note: you should read my other comment on this thread.