Current work culture is bizarre in cyber security. I am not personally very fan of it.
Nobody wants to work on defensive side. You are not getting either fame or money if you do your work well. The expectation is that you do your work perfectly. There is no actually measurements in place to prove that your good code prevented 100 data breaches!
But on the other hand, if you are on offensive side, sometimes find cool bugs, you get fame and money. Does not matter if there is a long break sometimes. Your goodness is measures based on how much money you got.
What does it mean? People start doing bug bounties. They hoard tools only for themselves to make more money, instead of releasing them to improve general security. They keep small bugs themselves so that they can be used in exploit chains to get bigger bounties.
If the reputation of the company is based on the participations of the bug bounty program, they start doing less and less in-house engineering and outsource the cyber security testing for bug bounty platforms.
And vicious cycle starts.