What I often see however, is SRE teams keep extremely understaffed (because "cost center") and often outsourced to offshore contractor in India - this basically means you can only keep the lights on via SRE team and cannot do anything else.
If you have a competent and fully staffed SRE Platform engineering team - you will NOT need a separate cybersecurity team.
But if company decided to cut costs on SRE folks, they then will have to invest heavily in cybersecurity team. At least because of mandated regulation (FedRAMP SOX HIPAA GDPR compliance disclosure etc) - it is easier to justify cyber budget, than the SRE budget
Plus recent laws mandate having CISO as a high level executive (chief incident scapegoat officer) with huge budget and disclosure of recent hacks etc