C2A Security names John Heldreth director of product security
C2A Security has appointed automotive cybersecurity veteran John Heldreth as director of product security to help guide its next-generation roadmap. The move underscores the company’s push beyond automotive into medical devices, industrial systems and other connected products facing tighter compliance and security demands.
Why it matters: - C2A Security is adding a leader with deep automotive, OEM and cybersecurity experience to shape product strategy for software-defined products. - The appointment comes as manufacturers face more complex software supply chains, new regulatory requirements and growing pressure to manage product security across the full lifecycle. - C2A Security is also aiming to extend its automotive product security approach into medical devices, industrial systems and other cyber-physical environments.
What happened: - C2A Security named John Heldreth director of product security. - Heldreth will work with the company’s leadership, product and engineering teams on the next generation product offering and roadmap. - The Jerusalem-based company made the announcement on Aug. 4, 2026. - Heldreth is founder and CEO of the Automotive Security Research Group, or ASRG.
The details: - Heldreth has worked in automotive engineering, cybersecurity operations, governance, product strategy and industry collaboration. - He previously held roles at Volkswagen, Porsche and Bosch. - C2A Security said Heldreth will bring market insight into the challenges manufacturers and product security teams face as software supply chains grow more complex. - Roy Fridman, CEO of C2A Security, said Heldreth’s background should help keep the product strategy aligned with customer needs and support expansion into adjacent industries as manufacturers prepare for regulations such as the EU Cyber Resilience Act. - Heldreth said success in software-defined products depends on timely, risk-based decisions using trusted data rather than fragmented information. - Heldreth said he will help shape solutions for automotive, medical devices, industrial systems, robotics and other connected product sectors. - C2A Security said its EVSec platform provides continuous, context-driven risk management across the product lifecycle. - The platform is designed to support security by design, automate compliance and threat analysis, manage vulnerabilities and bills of materials, and improve collaboration across product, security, engineering, IT and OT teams. - C2A Security says its platform uses AI capabilities to provide context intelligence for software-defined products in regulated industries. - The company says regulations including UN R155, FDA Section 524B and the EU Cyber Resilience Act are pushing manufacturers to demonstrate product security continuously. - C2A Security says EVSec gives manufacturers and suppliers one live view of security and compliance across the product lifecycle, shortens software release times and lowers compliance costs. - C2A Security says its customers and technology partners include Bayer, BMW Group, Daimler Truck AG, Ascensia, Elekta, NVIDIA, Siemens, HARMAN, Marelli, NTT Data and Deloitte. - The company was founded in 2016 by NDS/Cisco veteran Michael Dick and is headquartered in Jerusalem. - C2A Security received a CLEPA Innovation Award for its DevSecOps platform. - The company’s social media link is the company’s LinkedIn page.
Between the lines: - The hire signals C2A Security is leaning on automotive credibility to widen its addressable market. - Heldreth’s ASRG background also suggests C2A Security wants stronger industry ties and more direct feedback from the broader automotive cybersecurity community. - The regulatory references point to a market where compliance is becoming a product feature, not just a back-office obligation.
What's next: - Heldreth is expected to help turn industry requirements into product priorities. - C2A Security will likely use the hire to deepen customer and partner engagement while pushing EVSec into more regulated sectors. - The company’s roadmap now appears tied more closely to cross-industry product security and compliance demands.
Disclaimer: This article was produced by AGP Wire with the assistance of artificial intelligence based on original source content and has been refined to improve clarity, structure, and readability. This content is provided on an “as is” basis. While care has been taken in its preparation, it may contain inaccuracies or omissions, and readers should consult the original source and independently verify key information where appropriate. This content is for informational purposes only and does not constitute legal, financial, investment, or other professional advice.
Sign up for:
Israel Business Currents
The daily local news briefing you can trust. Every day. Subscribe now.
Check Your Email!
We sent a one-time activation link to: .
Confirm it's you by clicking the email link.
If the email is not in your inbox, check spam or try again.
Welcome back!
is already signed up. Check your inbox for updates.