In a sense, finding security bugs is a very specialized QA sub-discipline, which often requires a far deeper understanding about security than many QA engineers or developers possess. However, there is also a part of that organization which does feature work to systemically address the kinds of security issues they find.
Also, many large organizations like MS don't have many QA teams, preferring to push QA tasks onto developers, but still need specialized security teams. If you dig into the deep history of morse, they barely escaped being sacked when MS laid off the QA org circa 2017.
(I used to work on that team, but now work at another company doing a similar job)