It is possible to configure tasks that are to be executed on a managed device in the Schedule Editor.
For a task of the type Apply a Deployment Manager policy the option ApplySecurityPatchPolicy is available for configuration.
Add the following additional parameter to configure a scheduled task to ignore security packages when the policy is processed (see screenshot below):
-o ApplySecurityPatchPolicy=False
Comments