I haven't been in the industry that long, but I've encountered a few "security professionals"--auditors, penetration testers, etc. All of them have been totally incompetent; they could tell you the definition of, say, a SQL injection attack but had no idea how to really analyze a system. On the other hand, all of the great programmers I've met have had a really good grasp of security. I'm starting to think that if you don't write code, you're not qualified to audit it.