Fig Brings CI/CD Engineering to Security Operations
Fig expands its platform across the full SecOps engineering lifecycle, prioritizing resilience.
(July 21, 2026 – 3:25 pm)
(Image by: Fig)
Security operations landscapes are in constant flux, with new cloud services, data sources, automations, and detections emerging regularly. Changes to upstream systems can be unpredictable, presenting challenges for maintaining consistent detection pipelines and causing visibility gaps within organizations.
Fig believes the solution isn’t about generating more detections but managing change safely. They’ve introduced what they claim is the industry’s first complete SecOps engineering lifecycle, bringing a CI/CD-style workflow to Security Operations (SecOps) Engineers. This enables them to build, deploy, and continuously monitor changes across their environments.
Integrating Software Engineering Principles into SOCs
Fig essentially provides SecOps with a full engineering lifecycle for detections and configurations. Instead of manually crafting detections and configurations, engineers can specify the desired outcome. Fig analyzes live environments, suggests necessary modifications, assesses their potential impact before production deployment, and ensures continuous observability to verify the functioning of both new and existing detection flows.
Applying Software Development Practices to Security Operations
Instead of introducing another stand-alone security tool, Fig leverages practices familiar in software development—including testing, validation, and controlled deployment—to streamline the daily tasks of security operations teams.
Building on a Foundation of Security Data Lineage
Fig’s workflow is supported by a deterministic graph of its security data lineage, mapping every detection, data source, and connection throughout the SecOps infrastructure into a singular operational view. This granular understanding allows Fig to evaluate proposed changes within context, mitigating potential disruptions caused by complex evolving environments.
The aim is to minimize the risk of silent failures that could arise from these increasingly intricate security landscapes.
Speeding Up Everyday Security Engineering Tasks
Fig’s expanded platform is designed to accelerate various routine yet time-consuming security engineering tasks:
- Converting threat reports into detections and queries faster, enabling quicker responses to emerging threats.
- Simplifying SIEM migrations by allowing organizations to remain fully operational during the transition, reducing projects from months to weeks.