that is the typical OSS strawman, if you don't like it why don't you do it? if you are complaining, are you volunteering? if not you are not allowed.
We are not talking here of a random OSS project, I have contributed to some of those over the years in my off hours when I feel like working into some other environment than what I do at work, we are talking about a library that most of the internet depends on for security: do you really think it should be volunteers that should be working on it? don't you think that Google, Amazon, ebay, paypal, and all the major world banks could take 0.0001% of their profits and put together a fund to hire competent people to do this full time? and not just security researchers, project managers, QA, technical writers, etc.
OpenSSL/GnuTLS/... development is not something to be done in off hours, at off times in your company when you don't have other projects to do, it has to be done as your primary job description with no rush, no pressure, just making sure that things are done right and stay done right, with a proper process, proper QA and proper project management.
I have many years of defensive C development under my belt, I especially love passwords and associated issues, I have worked with crypto software before, but it's not something that I would want to risk doing at night when I am tired after a day at my "real job" and my brain is not at 100% efficency, hence why "I am not volunteering I see".