The person in charge of appsec is guaranteed to be many fiefdoms away from the sysadmins. In a lot of very large famous companies, you'd be wise to put money on the notion that the appsec guy hates the guys that manage the websites.
And vice versa! As a sysadmin I wouldn't want to give the private key to someone with the knowledge of how to use it for interception of the traffic it's protecting ( and possibly the opportunity!)