Honestly, 1 week sounds totally reasonable to me. If you’re at the point where you need an answer immediately or it’s going to delay your timelines, then you didn’t plan your timelines very well, or you waited too long to engage your security team. You have to keep in mind that while you might be laser-focused on your app and think it’s the highest priority, your security team is likely dealing with hundreds of apps, each of which all claim to be the highest priority. Triaging has to happen, and it doesn’t always go in your favor. It really sucks for everyone involved, but I don’t see a good fix for it.
The sweet spot is empowering teams to make most security decisions on their own so the capacity of security people can be spent more wisely and development teams don’t have to wait for an answer except for in very rare cases, but the pessimist in me thinks we’re already too far behind on this and technology (and the opportunity for new security dangers to arise) moves too fast for us to ever catch up.