It's a distinct skillset.
To whatever extent they might build software that's more secure than the average dev's, that really comes down to applying their security skills and toolset to their own software- thinking like an attacker- not any particular skill at software engineering.
Luck too.
The birthday lottery still plays a roll: being born with the particular set of predispositions, and the right family and environment to encourage strengthening those predispositions.
they are exploiting the 'quality' codebase written by your so-called average dev or software engineers
and since when software engineering does not take security into account?
Hard disagree. Maybe you can argue that they might not have skillset/experience of writing good quality code but they need to know the very in depth of each of the component from javascript to kernel. It's not a separate skill. It's the same skill as what senior dev do only the folks who write exploit need to understand allocations in bit level detail in each layer of the machine in which code is executed. eg I would recommend seeing the coding episodes of geohot who was a hacker and look how fast he could write the "ordinary" code like setting up website and other things.
Guaranteed to be 10x bugs to lines written.