Developers tend to think of security as about avoiding coding mistakes, and that's reflected in their idea that security is about pen testing, code review, tools, etc. Any security professional will tell you that these are valuable but only a small part of the big picture. Take a look at Microsoft's SDLC for a wider view of what it takes to weave security into every aspect of software development[1]
Probably the single most valuable thing most development organizations could do to improve security of applications is to do threat modeling[2][3]. It's especially valuable in the early stages of application design, but it can be applied at any time. Threat modeling can increase awareness of how an application's security assumptions interact with its overall architecture. Thinking through your application's threat model systematically is the first step to prioritizing mitigations.
Unfortunately, this is voodoo to most developers even though it really should be an intrinsic part of designing application architecture. I've heard people say there's a mental block because the kind of thinking required for security is almost the opposite of that required to design and construct systems. I don't believe that though. I think it's mostly a matter of training and historical accident that security is even a separate discipline. It shouldn't be.
[1] https://www.microsoft.com/en-us/sdl/
[2] https://msdn.microsoft.com/en-us/library/ff648644.aspx
[3] https://www.owasp.org/index.php/Application_Threat_Modeling