As a person whose straddled infosec and development, I always struggled with this. The multiple development machines is probably the best approach, but I've never truly seen it implemented correctly. I would love to not need admin access to my machine, but each time the companies I've worked for try this, it's always a struggle to do anything. This is everything from, "I need to modify/monitor core components of the operating system" to "The development tools came out with an update that needs to be installed." Most of the time, the response I've received was, "Enter a ticket, and we'll get to it." Often management seems to understand, "I'm waiting someone else" as "I'm behind, I'll work the weekend." You're right the downloading random things from the internet is an issue. Sadly I think a lot of this can be solved by the organization spending the money to buy all the needed tools and evaluate the correct open source ones, but there always seem to be budget and time constraints.
I think a lot of this stems from the fact that most of the managers in infosec for companies aren't developers and haven't ever been one. They really have no idea what developers really do. I'm not belittling them. It's just not the career path they took to get where they are. It's difficult to explain to them how frustrating being hindered is, and this causes a lot of good people to just leave an organization like that to find something better.