" " indicates required fields
JERUSALEM, Israel, August 4, 2026 – C2A Security, the context and AI-driven product security orchestration platform for software-defined products and cyber-physical systems, today announced that automotive and product security leader John Heldreth has joined the company as Director of Product Security.
In this strategic product role, John will work closely with C2A Security’s leadership, product and engineering teams to help shape the company’s next generation product offering and roadmap. He will bring direct market insight into the challenges manufacturers and product security organizations face as they manage increasingly complex software supply chains, evolving regulatory requirements and a rapidly changing threat landscape.
John brings experience spanning automotive engineering, cybersecurity operations, governance, product strategy and industry collaboration. He has held positions at leading automotive organizations, including Volkswagen, Porsche and Bosch, giving him first-hand insight into the operational and organizational challenges faced by global manufacturers and suppliers.
He is also the Founder and CEO of the Automotive Security Research Group (ASRG), a global community dedicated to advancing automotive cybersecurity through collaboration, research, education and the exchange of practical knowledge.
“John brings deep automotive cybersecurity expertise together with a broad understanding of the product security challenges facing manufacturers,” said Roy Fridman, CEO of C2A Security. “His experience across engineering, security operations, governance and industry collaboration will help ensure that our product strategy remains closely connected to real-world customer needs. It will also support our expansion into adjacent industries as manufacturers prepare for regulations such as the EU Cyber Resilience Act and address the growing convergence of product security, IT and operational technology.”
As part of his role, John will help C2A Security deepen its engagement with customers, partners and the broader market, translating industry requirements into clear product priorities. He will also help C2A apply the product security expertise it has developed in automotive to medical devices, industrial systems and other cyber-physical environments facing similar software supply chain, regulatory and lifecycle security challenges.
“Software-defined products have fundamentally changed how organizations across industries must approach cybersecurity,” said John Heldreth. “As software complexity grows and regulations reshape market requirements, success will depend on the ability to make timely, risk-based decisions using trusted data rather than fragmented information. C2A Security is building the intelligent platform manufacturers need to manage product cybersecurity and compliance at scale, and I am excited to help shape solutions that deliver measurable value across automotive, medical devices, industrial systems, robotics, and other connected product sectors.”
Johns’s appointment comes as C2A Security continues to expand its product security orchestration capabilities across automotive, medical devices, industrial systems and other cyber-physical industries. The company’s EVSec platform delivers continuous, context-driven risk management across the product lifecycle, helping organizations embed security by design, automate compliance and threat analysis, manage vulnerabilities and bills of materials, and improve collaboration across product, security, engineering, IT and OT teams.
Dynamic threat modeling and risk assessment aligned with global regulations
LLM-agnostic generative AI layer powering automation across every module
Aggregated threat feed contextualized against your actual products
Generate, manage, and triage all BOMs and vulnerabilities across the lifecycle
Quantitative optimization of mitigation strategy and security control allocation
Configurable dashboards and reports across every EVSec data layer
Extract software composition and risk from firmware and binaries without source code
Optimized anomaly detection for Ethernet and CAN, plus ECU runtime protection
Quantify and manage cybersecurity risk for products operating in the field
Enrich SOC events with deep product and architecture context
Context-driven test and validation with intelligent fuzzing, integrated into CI/CD
AI-powered static analysis integrated into CI/CD with reduced false positives
Foundational layer: cyber model, workspaces, and integration backbone to DevOps toolchain
Out-of-the-box and customizable workflows for regulatory and security processes
Centralized compliance management with evidence generated from live data