Fig Reframes SecOps Around Continuous Engineering as Security Environments Grow More Complex
Security operations teams are expected to respond quickly as new threats emerge, but the infrastructure behind that response is changing just as rapidly. New data sources are introduced, cloud services evolve, detections are added, and automations become part of increasingly interconnected workflows.
The challenge is that security infrastructure does not operate in isolation. A change in one part of the environment can affect another, potentially disrupting detection pipelines without immediately alerting the teams responsible for protecting the organization.
Fig is addressing that challenge by expanding its platform across what it describes as the complete SecOps engineering lifecycle. The company says its approach brings a CI/CD model to Security Operations (SecOps), allowing engineers to build, ship, and observe changes while maintaining greater confidence in the systems responsible for detection and response.
The move reflects a broader shift in security operations: as the technology stack becomes more complex, managing change itself is becoming a critical part of security engineering.
Treating Detection Changes Like Software
At its core, Fig is giving SecOps something it has never had: a complete engineering lifecycle for detections and configurations.
The workflow begins with the change an engineer wants to make. Rather than manually connecting systems and configuring infrastructure, the engineer describes the desired detection or configuration, and Fig analyzes the live environment to propose an implementation.
Before deployment, the proposed change is simulated and tested to evaluate its expected impact. Approved changes can then be deployed with version control and rollback capabilities, while continuous observability monitors detection flows after deployment.
The approach brings concepts that have become standard in software engineering into security operations. Testing and validation happen before production, changes can be rolled back, and ongoing monitoring continues after deployment.
For SecOps teams, the result is intended to be a more structured way to manage the infrastructure supporting detection and response.
The Role of Security Data Lineage
Fig’s platform is built on a deterministic graph of security data lineage that maps detections, data sources, and their connections throughout the SecOps environment.
The company views this lineage as the foundation for understanding how changes move through the infrastructure. By mapping the relationships between different components, Fig can evaluate proposed changes with greater context and assess how they might affect the broader detection pipeline.
That context becomes particularly important when changes originate outside the immediate control of the security team. Upstream or downstream systems can evolve independently, potentially creating problems that are difficult to identify until detection coverage has already been affected.
Continuous verification is designed to provide ongoing visibility into those relationships and help ensure detection flows continue working as intended.
Turning Security Work Into an Engineering Workflow
The platform is also intended to shorten the time required for several common SecOps activities.
Fig says security teams can turn threat reports into detections and queries more quickly, allowing them to address emerging threats without waiting through lengthy engineering processes. SIEM migrations can also be completed in weeks rather than months, according to the company, while organizations remain fully operational throughout the transition.
The platform’s data plane capabilities give teams greater control over data ingestion and storage spending without affecting live detections.
These capabilities point to a common objective: reducing the amount of manual infrastructure work required to keep security operations running, while allowing engineers to concentrate on detection logic and improving coverage.
Confidence Becomes Part of the Deployment Process
For Fig, speed is only one measure of an effective security engineering workflow. The company is equally focused on whether teams can trust the changes they make.
Jayme Hancock, Head of Security Operations and Engineering at AppLovin, said, “With Fig we build and ship accurate detection changes in minutes instead of weeks, without the endless plumbing.” He added, “My team builds with a confidence we’ve never had, and yeah, we’ve even started ‘vibe parsing.’”
The customer perspective reinforces the company’s argument that reducing the engineering effort around changes can also improve confidence in the resulting environment.
A Broader Bet on Security Operations Resilience
Fig’s platform expansion builds on its focus on Security Operations Resilience. The company has raised $38 million from Team8, Ten Eleven Ventures, and Crosspoint Capital, was named a finalist in the RSAC Innovation Sandbox, and says its technology has been deployed across dozens of Fortune 500 companies.
Founded by veterans of Google SecOps and Siemplify, Fig says its platform is informed by experience with large and complex security operations environments where changes can create unexpected failures.
Gal Shafir, Co-Founder and CEO of Fig, said the company wants to remove the perceived choice between speed and reliability. “Security teams shouldn’t have to choose between moving quickly and maintaining confidence in their SecOps Infrastructure,” he said. “Fig gives SecOps Engineers the same modern engineering workflow that software developers have long relied on. They can design changes with complete context, prove those changes work before deployment, and continuously verify that their security operations remain resilient as their environments evolve.”
As SecOps infrastructure becomes more interconnected, Fig’s approach suggests that resilience may increasingly depend on how organizations engineer change—not simply on how many security tools they deploy.


