Back to Feed
ToolsJul 21, 2026

Fig Expands SecOps Engineering Lifecycle as Security Teams Seek More Resilient Infrastructure

Fig Security expands its platform to cover the full engineering lifecycle for SecOps.

Summary

Fig Security has enhanced its platform to encompass the complete engineering lifecycle for Security Operations (SecOps). This expansion integrates CI/CD practices, enabling security teams to build, test, deploy, and continuously verify detections and configurations. The goal is to improve the resilience of security infrastructure against evolving environments and unexpected changes, ensuring reliable detection coverage.

Full text

SecurityFig Expands SecOps Engineering Lifecycle as Security Teams Seek More Resilient Infrastructure Learn how Fig adds testing, deployment, and continuous verification to SecOps, helping security teams keep detections reliable as infrastructure evolves. daily. byOwais SultanJuly 21, 20264 minute read Listen to this article 0:00 — ← 10s ▶ Play 10s → Speed 0.75× 1× 1.25× 1.5× 2× Voice Loading voices… Press play to start listening Security operations teams are managing environments that change almost as quickly as the threats they are designed to detect. New cloud services, data sources, detections, and automated processes are introduced continually, while systems upstream of the security stack can change with little warning. That creates a problem that is easy to overlook. A change does not have to be malicious or even particularly significant to cause damage. A routine infrastructure update can disrupt a detection pipeline, potentially leaving security teams with gaps in visibility before anyone realizes something has stopped working. Fig Security is aiming at that problem with an expanded platform that covers what the company describes as the full engineering lifecycle for Security Operations (SecOps). The approach brings CI/CD-style practices to SecOps, allowing engineers to build, ship, and observe changes while continuously checking that detection operations remain functional. The broader idea is to make resilience part of the way security infrastructure is engineered rather than something teams have to address after a failure. A Complete Engineering Lifecycle for SecOps At its core, Fig is giving SecOps something it has never had: a complete engineering lifecycle for detections and configurations. The workflow starts with an engineer describing the detection or configuration they want to create. Fig then evaluates the live environment and proposes a change based on its understanding of the existing infrastructure. Before deployment, proposed changes are simulated and tested to determine their expected impact. Once approved, engineers can deploy them with version control and rollback capabilities, while continuous observability monitors detection flows to verify that they continue working as intended. The process is designed to bring software engineering disciplines into security operations, giving teams a structured approach to testing and deploying changes rather than relying primarily on manual validation. Understanding the Infrastructure Behind Detection The foundation of this workflow is Fig’s security data lineage, which the company describes as a deterministic graph mapping detections, data sources, and the connections between them across the SecOps stack. This creates a broader view of the infrastructure surrounding each detection. Instead of evaluating changes in isolation, Fig can use the relationships mapped across the environment to assess how a proposed update could affect other components. That visibility also matters when changes occur outside the security team’s immediate control. An upstream system can evolve and unintentionally affect a downstream detection, while a change further along the pipeline can create a problem that is difficult to trace back to its source. Fig says its continuous verification capabilities are designed to help identify these issues before they undermine detection coverage. Faster Responses and Shorter Projects The platform’s expanded capabilities extend beyond individual infrastructure changes. Fig says security teams can translate threat reports into detections and queries faster, helping organizations implement protections without lengthy development cycles. The company is also targeting large-scale projects such as SIEM migrations. According to Fig, organizations can complete these transitions in weeks instead of months while keeping security operations fully operational during the process. Data management is another area covered by the platform. Teams can gain control over data ingestion and storage costs through the data plane without disrupting live detections. Together, the capabilities are intended to reduce the engineering burden associated with maintaining security operations and allow SecOps teams to spend more time on the logic behind their defenses. Building Speed Without Sacrificing Confidence Fig argues that faster security operations are not enough if teams cannot trust the infrastructure supporting them. Its workflow is therefore built around validating changes before production and monitoring them after deployment. Jayme Hancock, Head of Security Operations and Engineering at AppLovin, described the experience by saying, “With Fig we build and ship accurate detection changes in minutes instead of weeks, without the endless plumbing.” He added, “My team builds with a confidence we’ve never had, and yeah, we’ve even started ‘vibe parsing.'” The feedback speaks to the central proposition behind the platform: engineering teams can move faster when they have greater visibility into the changes they are making and confidence that those changes will continue working. Resilience as a Core Operating Principle The latest platform expansion builds on Fig’s broader focus on Security Operations Resilience. The company has raised $38 million from Team8, Ten Eleven Ventures, and Crosspoint Capital, was named an RSAC Innovation Sandbox finalist, and says its technology has been deployed across dozens of Fortune 500 companies. Fig was founded by veterans of Google SecOps and Siemplify, and the company says its approach was shaped by experience with some of the world’s largest and most complex security operations environments. Gal Shafir, Co-Founder and CEO of Fig, said security teams should not have to trade speed for confidence. “Security teams shouldn’t have to choose between moving quickly and maintaining confidence in their SecOps Infrastructure,” he said. “Fig gives SecOps Engineers the same modern engineering workflow that software developers have long relied on. They can design changes with complete context, prove those changes work before deployment, and continuously verify that their security operations remain resilient as their environments evolve.” As security infrastructure continues to expand and change, Fig is betting that the next evolution of SecOps will depend on engineering every change for resilience from the start. Owais Sultan Owais takes care of Hackread’s social media from the very first day. At the same time He is pursuing for chartered accountancy and doing part time freelance writing. View Posts CI/CDCybersecurityFigFig SecuritySecOps Leave a Reply Cancel reply View Comments (0) Related Posts Read More Security Cyber Attacks News American Express Cardholders Impacted by Third-Party Vendor Data Breach Another day, another third-party data breach! byWaqas Read More Security Gaming Malware This Ransomware tells users to play a popular Japanese game – That’s all You might have heard countless tales of hackers using malicious ransomware forcing users to pay huge amounts of… byJahanzaib Hassan Read More Privacy Security Mullvad VPN Introduces Mullvad Leta: A Privacy-Focused Search Engine The Mullvad Leta search engine is accessible exclusively to users with a paid Mullvad VPN account. byWaqas Read More Security Android Malware Xavier Malware Infects Hundreds of Android Apps on Google Play Store You might have heard researchers urging Android users not to download apps from a third party store since… byWaqas

Entities

Fig Security (product)SecOps (technology)CI/CD (technology)SIEM (technology)