That's the management problem right there. You should be able to get promotions for maintaining/improving a small product. The fact that you can't is what causes this endless shutdown mentality.
Ultimately, you really are never going to see innovation if the cost of launching a product is "staff the product literally forever, no matter if it is losing money or no longer aligned with priorities".
Also, this makes me wonder: does every project have at least one security engineer until it gets shut down?
Usually a specific project doesn't have dedicated security engineers but instead the engineers have to get approval from security engineers for their relevant designs.
This is probably different for teams dedicated to security like those that write fuzzers and the such.