So.... this is interesting. The answer is if they are strict authoritarians and go by the book, yes. There is no leeway. If they are flexible and are open to interpretation and intent then no... but then that leaves them open to risk.
Because of that most companies over time become very strict and unforgiving.
That's the most important question, and there's a pretty good case to be made for "yes". It's a severe error in judgment for a security engineer to co-opt an security notification system in order to spread personal messages. Not only is it spam, it desensitizes users to real warnings. (Imagine an email from Google where the subject is "SECURITY ISSUE WITH YOUR ACCOUNT" and the content is an ad for a Pixel). I probably would have given a strong warning rather than firing, but it's not unreasonable to be especially strict when dealing with security matters.