The naked truth of #cybersecurity
@beyondmachines1 I've been asked a few times at work now if I was interested in being the go-to person for security related development and I refused with the reason that it's basically a career dead end. No business wants to pay for proper security.

@withoutclass the go-to person is not a formal function, you get all the blame and no authority (however marginal) to drive change.

And in the long run chasing features will always trump any security concerns.