Heartbleed, and "goto fail" are bugs that any competent C developer could have found. You, me, the muffin man, the NSA, a bright undergraduate student. Anyone. These aren't vulnerabilities that you read about in a crypto journal. They are basic implementation bugs.
So why weren't they found by amateurs? (Well, perhaps the premise is false. Perhaps they were found by amateur attackers.) However I submit to you if true it is because people who are actually experts in cryptography do not generally spend their time looking for dumb implementation bugs. I'm sure some do, but many don't. Which is understandable--we want those people looking for weaknesses in AES or curve25519 or something.
Meanwhile we have a culture of abstinence-only crypto education, where everything crypto touches is a forbidden land that we shame any ordinary software developer for venturing into. Nobody found this bug because ordinary developers aren't there to find it. They're not there because they're told to leave.
You suggest "double down on amateurish" facetiously but I claim that amateur hour would have actually caught these two bugs, because any amateur can see them. Maybe it would have created more bugs, maybe not, but I think it would have stopped these two early.
What I think we need to do, and what we should have done a long time ago, is recognize that abstinence-only crypyotgraphy doesn't work. We need to define levels of risk. Writing your own crypto algorithm is Threat Level Red. Implementing a strong one from a spec is Threat Level Yellow. Implementing a high-level authentication scheme like TLS from a spec is Threat Level Green. Porting OpenSSL to a new architecture is Threat Level Blue.
Abstinence-only crypto education doesn't recognize that some people are going to do crypto anyway. It also doesn't recognize that "not enough eyes" is a threat model that objectively produces THE most serious vulnerabilities we have faced in recent years. Putting all our eggs in OpenSSL and telling ordinary developers to use it and not ask questions literally burned down the internet. I don't know what kind of bad scenario we were trying to avoid, but the one that actually happened was worse.
Some type of risk-aware model encourages people to get involved in a skill-appropriate way. That needs to be the goal of the crypto community right now; to capture the energy from software developers interested in cryptography (particularly due to recent world events) and do something useful with it; not turn them away and say "nothing to see here".