If you really want to do security, then my advice is to either look at some dedicated security consulting shops that do penetration testing (and be prepared to take a pay cut), or alternatively use your software development experience to pivot into an application security role. From there, you might find it easier to get involved with some offensive security efforts through that.
edit: They also give a ~$25k-$35k stipend plus tuition, security certs, books, etc. It's a pretty solid deal IMO.
They might still be doing virtual events, having some speakers etc. Get yourself known. I have been able to get junior people straight out of college/university into roles by getting them into the "networks". There's a worldwide shortage of security people, caused partly by the inability of the people who need them to efficiently hire them (other causes include wanting top-level skills for bottom level pay, and blaming lack of people for their own lack of willingness to pay).
The more you get known in your local security community, the better. After a while, perhaps they'll be interested in a talk from you about something as well - it gets you seen and known, and it's much easier to break into security when you're known.
Go to your local security meetups, network, meet people. Chances are most of the people you talk to are hiring or know people who are hiring.
Get yourself a blog, write about your security research, write about your experiences with CTFs.
Showing that you care about security enough to do it in your own time is worth more than any cert.
Definitely this. And if they like you, and their company isn't hiring, they might even be able to get them to hire you. Good and enthusiastic security people are hard to come by, so you take the ones you can get, if times are good and you think you might need more soon!
And even if they aren't hiring, chances are they will be able to make a personal introduction to someone who is hiring - at least in the local networks I've been involved in, there's more demand than there is supply, so people are generally pretty willing to help you make connections with the right people. And at the back of their mind, they will also be thinking how they can always go to you in future to get out of their current place(!)
But certs are an unfortunate necessity in a world where fresh college graduates without a days worth of experience in IT or Security are pre-filtering resumes. Certs ARE worth it, to get past HR. I always tell everyone who wants to get into security that the first infosec job is the hardest to get, and for that, you need to play the HR game, and that means a couple certs. You need to sit down in front of the hiring manager for an interview to get the job, your hiring manager will know your cert means nothing, almost guaranteed he never even asks you about any of them.
Your resume means everything to get in front of the manager, then your resume means jack shit to the manager. It is stupid, but is the world we live in.
You can get hired into infosec without the certs though, and that's know the hiring manager or know someone on the team you are applying for. Hiring managers can tell HR "I want to interview Joe Somebody, he said he will apply this week", and in security, id say more than 50% of the hires are indeed that. So to do this, go to the local professional meetups that meet monthly, go out for beers with the people, go to the local conferences and make friends with many people already in the industry, maybe do a talk at the meetups or local conference. Then when a position opens up at a place where there is someone you know, you now can get an interview.
But you really should be doing both at once. Most competent developers or IT people can pass Sec+ blindfolded, you most certainly do not have to take the class, at MOST skim the study guide book once, and your almost guaranteed to pass. It is a joke, everyone in the industry knows it, yet if you could dramatically increase your chances of getting an interview while you are taking the time to develop those relationships, what idiot wouldn't?
But I've been in security over a decade, and have hired at smaller boutique pentest companies, and multi billion dollar companies. In all cases, the CVs/resumes come straight to us, they never go via HR.
Despite this, as you say, I've usually seen CVs/resumes come straight to the hiring team - the first thing an effective security lead does ensure there's no pre-screening on CVs, as they want to see the "unconventional" CVs as much as the conventional ones.
There's also companies that actively have their techies go out and fly the flag, post on the /r/netsec or HN hiring thread, and give a point of contact straight to a personal or team mailbox.