
Security operations teams are constantly adapting. New data sources come online, cloud services evolve, detections are added, and automation becomes increasingly embedded in the security stack. At the same time, upstream systems can change independently, creating dependencies that security teams may not always be able to anticipate.
The result is a difficult operational reality: even a small infrastructure update can have consequences for detection pipelines. When those changes are not properly tested or monitored, organizations can lose visibility into threats without immediately realizing that their security coverage has been affected.
Fig‘s latest platform expansion is designed to address that challenge by bringing what the company describes as a complete engineering lifecycle to Security Operations (SecOps). The approach gives SecOps Engineers a way to build, ship, and observe changes through a workflow modeled on continuous integration and continuous delivery (CI/CD).
Rather than viewing resilience as something that follows deployment, Fig is positioning it as an integral part of the engineering process.
A Different Model for Building Detections
At its core, Fig is giving SecOps something it has never had: a complete engineering lifecycle for detections and configurations.
The workflow begins with an engineer describing the change they want to make. Fig analyzes the existing environment and proposes an implementation based on the infrastructure already in place.
Before the change reaches production, it is simulated and tested to determine its expected impact. Once approved, the update can be deployed with version control and rollback capabilities, providing teams with greater control over the release process.
The lifecycle continues after deployment. Continuous observability verifies that detection flows remain operational, giving security teams ongoing visibility into whether changes have affected the environment as intended.
The approach brings practices commonly associated with software development into security operations, including testing before production, controlled deployment, versioning, rollback, and continuous monitoring.
Mapping the Connections Behind Security Operations
The platform is built on Fig’s security data lineage, which the company describes as a deterministic graph that maps detections, data sources, and the connections between them throughout the SecOps infrastructure.
That graph provides the context needed to understand how different elements of the security stack relate to one another. When a proposed change is evaluated, Fig can consider its potential impact on the broader environment rather than looking at an individual detection or configuration in isolation.
This is particularly relevant as organizations rely on increasingly interconnected infrastructure. Changes made upstream or downstream can affect detection pipelines in ways that may not be immediately obvious.
Fig says its continuous verification capabilities are intended to help ensure that these flows continue working as infrastructure evolves, reducing the risk of silent failures that can create gaps in detection coverage.
More Efficient Security Engineering
The expanded platform also targets some of the time-consuming projects that security engineering teams manage.
Fig says threat reports can be converted into detections and queries faster, allowing organizations to respond to emerging threats without waiting through lengthy development cycles. The company also says its approach can help organizations complete SIEM migrations in weeks rather than months while remaining operational throughout the transition.
Teams can also use the data plane to gain greater control over data ingestion and storage costs without affecting live detections.
The common thread is reducing the amount of infrastructure work required to maintain security operations, allowing engineers to focus more directly on the logic and coverage of their defenses.
A Customer View of the Shift
For organizations responsible for maintaining detection engineering at scale, the ability to make changes quickly is only useful if those changes can be trusted.
Jayme Hancock, Head of Security Operations and Engineering at AppLovin, said, “With Fig we build and ship accurate detection changes in minutes instead of weeks, without the endless plumbing.” He added, “My team builds with a confidence we’ve never had, and yeah, we’ve even started ‘vibe parsing.'”
The comments reflect the central premise of Fig’s approach: reducing the complexity around infrastructure changes can help security teams move faster while maintaining confidence in the systems responsible for detection.
Engineering Resilience Into the SOC
Fig’s platform expansion builds on its focus on Security Operations Resilience. The company has raised $38 million from Team8, Ten Eleven Ventures, and Crosspoint Capital, was named a finalist in the RSAC Innovation Sandbox, and says its technology has been deployed across dozens of Fortune 500 companies.
Founded by veterans of Google SecOps and Siemplify, Fig says its platform was developed around the challenges of maintaining complex security operations environments where changes can have consequences beyond the systems being directly modified.
Gal Shafir, Co-Founder and CEO of Fig, said the company is focused on removing the tradeoff between speed and confidence. “Security teams shouldn’t have to choose between moving quickly and maintaining confidence in their SecOps Infrastructure,” he said. “Fig gives SecOps Engineers the same modern engineering workflow that software developers have long relied on. They can design changes with complete context, prove those changes work before deployment, and continuously verify that their security operations remain resilient as their environments evolve.”
For Fig, the next stage of security operations is not simply about adding more technology. It is about building an engineering process capable of keeping the entire security environment reliable as that technology and the threats it is designed to address continues to change.