Hiring people is difficult as there is lack of supply of talented people. We hire InfoSec on contract basis not full-time and they don't join such meetings due to the nature of the contract. So all the responsibility fell on me to defend our technical decisions at that point in time.
I'm working on building out the engineering culture / awareness within management now, to ensure these things do not happen, and I don't have to be questioned as to why we cannot install "google tag manager" in our front-end.
It all comes down to creating awareness, and making people understand. Fortunately for me our CEO gets it, he ended up siding with me.
To me, this is an even more concerning issue. But then, I have no idea how the finance services world works, so maybe this is more common than I think?
Outsourced CISO/InfoSec is a valid and reasonable thing for some companies.
If I was running a financial services startup, those groups would be near the front of my list in terms of internal hiring.
But again, since it's not always easy to find the right people I end up having to fill in for everything we don't have a team member to execute on.
Usually I try to reason with management first. If it can be resolved internally we would not include outside consultants, however if it gets serious beyond something we can handle internally we would ask outside consultant to come in.