Comment Re: Nobody wants to look at legacy source code (Score 5, Insightful) 55
Normally, developers are focused on making the product do something, but security is the inverse: it's making sure the product cannot do some things.
It's difficult enough to hire good developers who can make products that do stuff, but hiring ones can ensure it doesn't do anything bad requires that you find the people who really knows their shit and have the imagination to identify all the things a product shouldn't do.
Likewise, organizational leadership, project management, QA, etc, have got to be bought into it.