This is simply not true. Drupal.org has a dedicated security team monitoring all security problems in core and contributed modules. The fact that drupal is opensource makes it when well managed even more secure than closed source systems. Getting drupal secure is all about selecting the right implementation partner that knows how to take care of things.
Do you want to become a involved in drupal? There are a couple of ways to get a drupal job. The fastest way to start get a drupal job is try and find someone who can show you around. If you have been to drupal.org you might feel a little overwhelmed. The whole drupal universe is big, very big and it is difficult to figure out what you need to do and even more important what you want to do.