Fig Expands Platform Across the Full SecOps Engineering Lifecycle, Making Resilience the Default


Fig Expands Platform Across the Full SecOps Engineering Lifecycle, Making Resilience the Default Image by: Fig

Security operations environments are constantly evolving. New cloud services, data sources, automations, and detections are introduced on a regular basis, while upstream systems can change without warning. Although these updates are intended to improve security, they can also create unintended consequences by disrupting detection pipelines and leaving organizations with visibility gaps.

Fig believes the problem is less about creating more detections and more about managing change safely. To address that challenge, the company has introduced what it describes as the industry’s first complete SecOps engineering lifecycle, bringing a CI/CD-style workflow to Security Operations (SecOps) Engineers so they can build, deploy, and continuously observe changes across their environments.

Bringing Software Engineering Principles to the SOC

At its core, Fig is giving SecOps something it has never had: a complete engineering lifecycle for detections and configurations. Instead of requiring engineers to manually build detections and configurations, the platform allows them to describe the outcome they want. Fig analyzes the live environment, proposes the necessary changes, and evaluates their potential impact before anything reaches production.

Every proposed update is simulated and tested before deployment, according to the company. Once approved, changes can be deployed with version control and rollback capabilities, while continuous observability verifies that both new and existing detection flows continue operating as expected.

The 💜 of EU tech

The latest rumblings from the EU tech scene, a story from our wise ol' founder Boris, and some questionable AI art. It's free, every week, in your inbox. Sign up now!

Rather than introducing another standalone security tool, Fig is applying practices familiar to software developers, including testing, validation, and controlled deployment, to the day-to-day work of security operations teams.

A Foundation Built on Security Data Lineage

Supporting the workflow is what Fig describes as a deterministic graph of its security data lineage. The platform maps every detection, data source, and connection throughout the SecOps infrastructure into a single operational view.

This detailed understanding of the environment enables Fig to evaluate proposed changes with context, helping determine how updates may affect the broader detection pipeline. According to the company, continuous verification ensures those pipelines continue functioning properly even as infrastructure changes occur upstream or downstream.

The objective is to reduce the risk of silent failures that can occur when security environments become increasingly complex.

Speeding Up Everyday Security Engineering

The expanded platform is designed to accelerate several routine but time-intensive security engineering tasks.

Fig says security teams can transform threat reports into detections and queries much faster than traditional workflows allow, enabling organizations to respond more quickly to emerging threats. The platform is also intended to simplify SIEM migrations by allowing organizations to remain fully operational throughout the transition, reducing projects that typically take months to a matter of weeks.

In addition, organizations can gain greater control over the data plane, making it easier to manage data ingestion and storage costs without affecting live detections or disrupting existing workflows.

Customer Experience

Jayme Hancock, Head of Security Operations and Engineering at AppLovin, said the platform has significantly changed how his team approaches detection engineering. “With Fig we build and ship accurate detection changes in minutes instead of weeks, without the endless plumbing,” he said. “My team builds with a confidence we’ve never had, and yeah, we’ve even started ‘vibe parsing.‘”

The experience reflects Fig’s broader goal of reducing engineering overhead while giving teams greater confidence that changes will perform as expected once deployed.

Expanding the Vision for Security Operations Resilience

The latest announcement builds on Fig’s broader focus on Security Operations Resilience. Since emerging from stealth, the company has raised $38 million from Team8, Ten Eleven Ventures, and Crosspoint Capital, was named an RSAC Innovation Sandbox finalist, and says its platform has been adopted by dozens of Fortune 500 organizations.

Founded by veterans of Google SecOps and Siemplify, Fig developed the platform around the idea that every infrastructure change should be designed with full context, validated before deployment, and continuously monitored afterward. The team’s leadership previously held key roles in global security architecture for Google Cloud Security.

As Co-Founder and CEO Gal Shafir explained, “Security teams shouldn’t have to choose between moving quickly and maintaining confidence in their SecOps Infrastructure. Fig gives SecOps Engineers the same modern engineering workflow that software developers have long relied on. They can design changes with complete context, prove those changes work before deployment, and continuously verify that their security operations remain resilient as their environments evolve.

By bringing modern engineering workflows into the SOC, Fig is positioning its platform to help security teams manage increasingly dynamic environments while maintaining confidence that critical detection and response capabilities remain intact through every change.

Get the TNW newsletter

Get the most important tech news in your inbox each week.