Press play to start listening
Security operations teams are managing environments that change almost as quickly as the threats they are designed to detect. New cloud services, data sources, detections, and automated processes are introduced continually, while systems upstream of the security stack can change with little warning.
That creates a problem that is easy to overlook. A change does not have to be malicious or even particularly significant to cause damage. A routine infrastructure update can disrupt a detection pipeline, potentially leaving security teams with gaps in visibility before anyone realizes something has stopped working.
Fig Security is aiming at that problem with an expanded platform that covers what the company describes as the full engineering lifecycle for Security Operations (SecOps). The approach brings CI/CD-style practices to SecOps, allowing engineers to build, ship, and observe changes while continuously checking that detection operations remain functional.
The broader idea is to make resilience part of the way security infrastructure is engineered rather than something teams have to address after a failure.
A Complete Engineering Lifecycle for SecOps
At its core, Fig is giving SecOps something it has never had: a complete engineering lifecycle for detections and configurations.
The workflow starts with an engineer describing the detection or configuration they want to create. Fig then evaluates the live environment and proposes a change based on its understanding of the existing infrastructure.
Before deployment, proposed changes are simulated and tested to determine their expected impact. Once approved, engineers can deploy them with version control and rollback capabilities, while continuous observability monitors detection flows to verify that they continue working as intended.
The process is designed to bring software engineering disciplines into security operations, giving teams a structured approach to testing and deploying changes rather than relying primarily on manual validation.
Understanding the Infrastructure Behind Detection
The foundation of this workflow is Fig’s security data lineage, which the company describes as a deterministic graph mapping detections, data sources, and the connections between them across the SecOps stack.
This creates a broader view of the infrastructure surrounding each detection. Instead of evaluating changes in isolation, Fig can use the relationships mapped across the environment to assess how a proposed update could affect other components.
That visibility also matters when changes occur outside the security team’s immediate control. An upstream system can evolve and unintentionally affect a downstream detection, while a change further along the pipeline can create a problem that is difficult to trace back to its source.
Fig says its continuous verification capabilities are designed to help identify these issues before they undermine detection coverage.
Faster Responses and Shorter Projects
The platform’s expanded capabilities extend beyond individual infrastructure changes. Fig says security teams can translate threat reports into detections and queries faster, helping organizations implement protections without lengthy development cycles.
The company is also targeting large-scale projects such as SIEM migrations. According to Fig, organizations can complete these transitions in weeks instead of months while keeping security operations fully operational during the process.
Data management is another area covered by the platform. Teams can gain control over data ingestion and storage costs through the data plane without disrupting live detections.
Together, the capabilities are intended to reduce the engineering burden associated with maintaining security operations and allow SecOps teams to spend more time on the logic behind their defenses.
Building Speed Without Sacrificing Confidence
Fig argues that faster security operations are not enough if teams cannot trust the infrastructure supporting them. Its workflow is therefore built around validating changes before production and monitoring them after deployment.
Jayme Hancock, Head of Security Operations and Engineering at AppLovin, described the experience by saying, “With Fig we build and ship accurate detection changes in minutes instead of weeks, without the endless plumbing.” He added, “My team builds with a confidence we’ve never had, and yeah, we’ve even started ‘vibe parsing.'”
The feedback speaks to the central proposition behind the platform: engineering teams can move faster when they have greater visibility into the changes they are making and confidence that those changes will continue working.
Resilience as a Core Operating Principle
The latest platform expansion builds on Fig’s broader focus on Security Operations Resilience. The company has raised $38 million from Team8, Ten Eleven Ventures, and Crosspoint Capital, was named an RSAC Innovation Sandbox finalist, and says its technology has been deployed across dozens of Fortune 500 companies.
Fig was founded by veterans of Google SecOps and Siemplify, and the company says its approach was shaped by experience with some of the world’s largest and most complex security operations environments.
Gal Shafir, Co-Founder and CEO of Fig, said security teams should not have to trade speed for confidence. “Security teams shouldn’t have to choose between moving quickly and maintaining confidence in their SecOps Infrastructure,” he said.
“Fig gives SecOps Engineers the same modern engineering workflow that software developers have long relied on. They can design changes with complete context, prove those changes work before deployment, and continuously verify that their security operations remain resilient as their environments evolve.”
As security infrastructure continues to expand and change, Fig is betting that the next evolution of SecOps will depend on engineering every change for resilience from the start.