So much of main line security practice is cargo cultism. There is so little use of actual research and data on how compromises actually happen. Somebody just gets the idea something is good for security and it sticks. No rationale needed.
My theory is that security is the least desirable part of the entire software engineering stack - it’s boring, has a lot of blame and liability potential, and it’s a cost center. Heck at least infrastructure folks get to brag about things like cost optimizations.
As a result it seems to me that security attracts the kind of people who view it as a way to wear a digital uniform and badge.
CISSP will have you learn the required strength of a light bulb to light the alley behind the office. OSCP will introduce you to overflowing a buffer and pwning a remote service...
I know which one I find preferable to learn :)