Fig Introduces Full SecOps Engineering Lifecycle as Security Teams Seek CI/CD-Style Control
Security operations teams have long faced a difficult balancing act. They need to respond quickly as threats, technologies and infrastructure evolve, but the same changes that help organizations adapt can also introduce new risks into the systems responsible for detecting those threats.
Fig is taking aim at that challenge with a new approach to Security Operations Resilience, announcing what it calls the full SecOps engineering lifecycle. The company says its platform enables Security Operations Engineers to build, ship and observe detection and configuration changes across infrastructure, bringing a CI/CD-style workflow to security operations.
The announcement reflects a broader shift toward applying engineering principles to the security operations center. Rather than treating changes as isolated updates, Fig’s platform is designed to provide context across the SecOps environment, test proposed modifications before they reach production and continuously monitor what happens afterward.
The Problem With Constant Change
Modern security operations environments are rarely static. New data sources, detection rules, automations and cloud services are introduced regularly, while changes to upstream systems can occur without warning.
That creates a challenge for SecOps teams. A change that appears small in isolation can have consequences elsewhere in the detection pipeline, potentially causing a security control to stop working without immediately making the problem obvious.
Fig’s answer is built around security data lineage, which the company describes as a deterministic graph of the entire SecOps infrastructure. The system maps detections, data sources and the connections between them into a single view of detection flows.
The goal is to provide SecOps Engineers with a detailed understanding of how their infrastructure fits together before they make a change. Fig says the lineage gives the platform visibility into the infrastructure “down to the inch,” allowing it to account for both upstream and downstream dependencies.
That context becomes the foundation for the company’s engineering workflow. A SecOps Engineer describes the change they want, and Fig analyzes the live environment before proposing an implementation. The proposed change is then simulated and tested to assess its impact before production.
Once it is ready, the change can be deployed with version control and rollback capabilities. Fig’s continuous observability then monitors detection flows to confirm that both existing and newly introduced processes continue to operate as intended.
A Different Way to Handle SecOps Work
Fig’s approach is designed to address more than individual detection updates. The company says its capabilities can help teams turn threat reports into detections and queries intended to protect their environments immediately.
The platform is also positioned as a way to simplify large-scale infrastructure changes. According to Fig, SIEM migrations can be completed in weeks rather than months while remaining fully operational throughout the process.
Data management is another part of the company’s proposition. Fig says its full control over the data plane allows teams to determine ingest and storage spending without having to modify live detections.
For security teams, the distinction is important. Instead of spending time managing the plumbing required to implement and maintain changes, SecOps Engineers can focus on the logic behind those changes while Fig handles the surrounding infrastructure workflow.
The approach is already being used by organizations including AppLovin. Jayme Hancock, Head of Security Operations and Engineering at the company, described the difference in practical terms: “With Fig, we build and ship accurate detection changes in minutes instead of weeks, without the endless plumbing. My team builds with a confidence we’ve never had, and yeah, we’ve even started ‘vibe parsing.’”
Moving Toward Resilient Security Operations
The announcement also builds on Fig’s broader mission to make security operations more resilient as organizations contend with an accelerating threat landscape.
The company was founded by veterans of Google SecOps and Siemplify who, according to Fig, witnessed how changes could silently break complex SOC environments. Its platform is intended to address that problem by ensuring changes are made with context, validated before deployment and continuously checked afterward.
Fig’s trajectory has also included $38 million in funding from Team8, Ten Eleven Ventures and Crosspoint Capital. The company has been named an RSAC Innovation Sandbox finalist and says its platform has been deployed across dozens of Fortune 500 companies.
For Gal Shafir, Co-Founder and CEO of Fig, the objective is to remove the perceived tradeoff between speed and operational confidence.
“Security teams shouldn’t have to choose between moving quickly and maintaining confidence in their SecOps Infrastructure,” said Shafir. “Fig gives SecOps Engineers the same modern engineering workflow that software developers have long relied on. They can design changes with complete context, prove those changes work before deployment, and continuously verify that their security operations remain resilient as their environments evolve.”
As security infrastructure becomes increasingly dynamic, Fig is betting that the next evolution of the SOC will require more than adding new tools. Its vision is to give the engineers responsible for security operations a repeatable lifecycle for managing change—one that treats building, deploying and observing security infrastructure as connected parts of the same engineering process.


