CI/CD Reshaped Software Engineering. Fig Wants It to Do the Same for the SOC

CI/CD Reshaped Software Engineering. Fig Wants It to Do the Same for the SOC

Software teams stopped shipping code by hand a long time ago. Continuous integration and continuous delivery gave developers a way to build, test, and release changes on a loop, with automated checks and a clear path to roll back when something went wrong. Security operations never got that treatment. Detection engineering has largely stayed manual, slow, and fragile, held together by scripts and institutional memory.

Fig is trying to close that gap. The company announced today the full SecOps engineering lifecycle, which it describes as the first true CI/CD for security operations, letting Security Operations engineers build, ship, and observe every change with confidence.

Borrowing a Proven Idea

The parallel to software development is deliberate. Developers rely on a modern engineering workflow that Fig is now extending to the SOC. An engineer describes the change they want. Fig analyzes the live environment and proposes it. That proposal is simulated and tested to prove its impact before it reaches production. Deployment is a single click, backed by full version control and rollback. Continuous observability then confirms that every detection flow, current and new, works as intended.

Gal Shafir, Co-Founder and CEO of Fig, made the analogy explicit. "Security teams shouldn't have to choose between moving quickly and maintaining confidence in their SecOps Infrastructure," he said. "Fig gives SecOps Engineers the same modern engineering workflow that software developers have long relied on. They can design changes with complete context, prove those changes work before deployment, and continuously verify that their security operations remain resilient as their environments evolve."

The Reason SecOps Was Harder

There is a reason CI/CD arrived late to security operations. SecOps environments change constantly. New data sources, detections, automations, and cloud services show up daily, and upstream systems change without warning. A minor update can silently break a detection pipeline and leave a gap that keeps a team from detecting and responding to threats. Testing a change in that kind of moving environment is genuinely hard, because the ground shifts underneath it.

Fig's foundation is meant to hold that ground still. The platform is rooted in security data lineage, a deterministic, ground-truth graph of the SecOps infrastructure. Every detection and data source is mapped into a single flow. The lineage keeps all parts of the pipeline running as intended through any change, upstream or downstream, and it is why the company says it knows the infrastructure down to the inch.

What the Loop Delivers

With that foundation, the familiar payoffs of a good engineering pipeline start to appear in the SOC. Threat reports become detections and queries that protect the environment today, not next quarter. SIEM migrations complete in weeks instead of months and stay fully operational throughout. Full control over the data plane lets teams dictate ingest and storage spend without touching live detections.

The people doing the work feel the shift first. Jayme Hancock, Head of Security Operations and Engineering at AppLovin, described the change in tempo. "With Fig, we build and ship accurate detection changes in minutes instead of weeks, without the endless plumbing," he said. "My team builds with a confidence we've never had, and yeah, we've even started 'vibe parsing.'"

From Launch to Lifecycle

Fig framed today's news as the natural evolution of the promise it launched with just months ago. Since then the company has raised $38 million from Team8, Ten Eleven Ventures, and Crosspoint Capital, earned a spot as an RSAC Innovation Sandbox finalist, and deployed across dozens of Fortune 500 companies. Its founders are veterans of Google SecOps and Siemplify who modernized some of the world's largest and most complex SOCs and saw firsthand what silently breaks inside them.

Why the Analogy Holds

The value of the software comparison is that it sets a clear bar. Developers expect to design with context, prove a change before it ships, and verify it afterward. Fig's argument is that security operations should expect the same, and that the reason they have not is a missing foundation rather than a lack of ambition. With detection flows mapped end to end, the discipline that reshaped software delivery becomes possible in the SOC. The company describes the result as a security operation that is agile by design and resilient by default, where change powers the SOC instead of breaking it.