In my experience it’s really up to technical leadership to highlight what will happen if security flaws are ignored. If more senior leadership continues to ignore these issues, then it’s a culture issue and I wouldn’t stick around.
Surely it’s all about risk mitigation; some out-of-date NPM package with a minor flaw might cause the can to be kicked, but a major flaw with demonstrable consequences should get priority.