Clear up security release developer workflow
Created as a follow up to https://gitlab.slack.com/archives/C248YCNCW/p1613739672214400 (internal)
It's not always clear which statement applies to backports and which one applies to the default branch MR so I moved things around a big with the hope of making it clearer.