Fig Grows Its Platform to Cover Every Stage of SecOps Engineering, Making Resilience the Default State
Security operations teams are under constant pressure to keep pace with an environment that changes every day. New data sources, cloud services, detections, and automations are continually introduced, while upstream systems evolve without warning. Even seemingly minor updates can disrupt detection pipelines, creating gaps that leave organizations vulnerable to threats.
To address that challenge,
At its core, Fig is giving SecOps something it has never had: a complete engineering lifecycle for detections and configurations. Rather than manually connecting multiple systems and workflows, engineers describe the change they want, while Fig analyzes the live security environment and generates a proposed implementation.
According to Fig, every proposed change is simulated and tested before reaching production. Once validated, the update can be deployed with version control and rollback capabilities, while continuous observability verifies that both existing and newly introduced detection flows continue operating as intended.
The approach aims to bring the same development principles that software engineering teams have relied on for years into the security operations center (SOC), where infrastructure changes often carry significant operational risk.
The platform is built on what Fig describes as a deterministic graph of security data lineage. This graph maps every detection, data source, and the connections between them into a single flow, providing a comprehensive view of how security operations function across the environment.
Because the platform understands relationships throughout the SecOps stack, Fig can analyze infrastructure in detail before proposing changes. The company positions this visibility as the foundation for maintaining resilience, even as upstream or downstream systems evolve over time.
Continuous verification is intended to ensure that detection pipelines remain operational after every deployment, reducing the likelihood that infrastructure changes silently disrupt security coverage.
Beyond managing day-to-day changes, the new capabilities are designed to accelerate several common SecOps tasks.
According to Fig, security teams can convert threat reports into detections and queries much faster, enabling organizations to respond to emerging risks without waiting through lengthy engineering cycles. The platform is also intended to simplify SIEM migrations by allowing organizations to complete transitions in weeks rather than months while maintaining operational security throughout the process.
Fig also says teams gain greater control over the data plane, enabling them to manage data ingestion and storage costs without affecting live detections.
The company summarizes the model simply: security engineers provide the detection logic while the platform handles the underlying operational complexity.
Jayme Hancock, Head of Security Operations and Engineering at AppLovin, described the impact the platform has had on his team's workflow.
"With Fig we build and ship accurate detection changes in minutes instead of weeks, without the endless plumbing," said Jayme Hancock, Head of Security Operations and Engineering at AppLovin. "My team builds with a confidence we've never had, and yeah, we've even started 'vibe parsing.'"
The comment reflects one of the central themes of the announcement: reducing the engineering overhead traditionally associated with maintaining modern security operations.
The launch builds on Fig's broader focus on Security Operations Resilience, an area the company has emphasized since emerging from stealth. Earlier this year, the company announced $38 million in funding from Team8, Ten Eleven Ventures, and Crosspoint Capital, became a finalist in the RSAC Innovation Sandbox, and said its platform has been deployed across dozens of Fortune 500 organizations.
Founded by veterans of Google SecOps and Siemplify, Fig says its platform was developed to address operational failures that often occur as security environments grow more complex. Rather than treating infrastructure changes as isolated events, the company aims to ensure every modification is designed with context, validated before deployment, and continuously monitored afterward.
"Security teams shouldn't have to choose between moving quickly and maintaining confidence in their SecOps Infrastructure," said Gal Shafir, Co-Founder and CEO of Fig.
Fig gives SecOps Engineers the same modern engineering workflow that software developers have long relied on. They can design changes with complete context, prove those changes work before deployment, and continuously verify that their security operations remain resilient as their environments evolve.
This story was distributed as a release by Jon Stojan under HackerNoon’s Business Blogging Program.