I would argue, security needs to be a part of planning day 1 rather than looked at as a bolt on prior to involving upper management. It needs to be treated as a core functionality rather than an external concept. The biggest issue I see is we are patching and finding fixes for something that could easily be remedied if address before engineering takes place. Most firms i've worked with put it on the back burner or are stuck with the notion of i'm an engineer i'm smart so deal with it.