Does it really matter that they are/are not security professionals? Virgin Mobile is a major corporation, and (if I understand the vulnerability correctly) are willing to let a unique IP ping their server 1MM times in a day. Rate limiting software is open-source and easy to come by. How does Virgin mobile prevent DDOS attacks if this vulnerability exists?
Just because they're a major corporation doesn't mean anyone with any clout gives a shit about whether or not customer logins are being brute forced, or if their servers can be DDOS'd. Even if somebody cared to mention it, somebody else would mention that it's too expensive, they're not getting attacked right now, and there's more important problems to worry about, so it gets ignored. This is not just cynicism on my part - this is how most companies operate. When they start losing money they'll start caring about security.
Oh, and DDOS has nothing to do with rate limiting. If you fill up a pipe with incoming packets it's going to become unresponsive. There's no real way to stop it, but multi-homing, global distribution and some tricks administered by DDOS mitigation companies can help.