If they did it competently, there is no reason they couldn't implement their own crypto encapsulation.
As far as why they rolled their own... have you ever actually tried to use IPSec? It's a usability nightmare. It's also problematic in containers due to container permission issues. I suppose they could have used DSSL (datagram SSL) but that'd probably add more overhead than what they did.
I see little real world evidence that this "let the pros handle it" attitude toward crypto is helping.