When I have Organic Maps running in the foreground and try to lock the screen with the HW button, the screen turns off but the phone doesn't get locked properly. All it takes is to turn the screen on and I'm back in the app - no PIN, password, fingerprint etc. needed. Then, if I try to access anything else, the phone (correctly) switches to the lockscreen.
I can only reproduce this with Organic Maps (Pixel 9) but they have no permissions granted. Regardless, it seems like a security issue of the OS to me. It's possible that this happens with some other (even more sensitive) apps and I think you should know.