I find this attitude kind of depressing. When I was in CS undergrad I thought about going into security because it seemed like this thing where you needed a bunch of systems background. To understand some exploits e.g. [0] you'd need hardware-related knowledge like branch prediction and memory hierarchy. Or something like stack smashing you'd need to know the process memory model and maybe some assembly
It seems to me like security is split into two camps: the people who are out there in the wild who find exploits and the "bootcamp" crowd
[0] https://en.wikipedia.org/wiki/Spectre_(security_vulnerabilit...