In what way is this not strictly better for the defender than if that same process was running as SYSTEM?
I don't think limiting the capabilities of a child process (even by running it as "SYSTEM_LITE") impacts its scheduling priority, security settings, etc. It would depend on the policy around the process.