" " indicates required fields
C2A Security is a fast-moving, industry-shaping startup leading innovation in product security. We help global software-defined product companies turn cybersecurity into a competitive advantage. We offer a flexible work model, including in-office, hybrid, or remote. Your impact matters more than your location.
We are progressively building the AI capabilities within our platform and exposing our platform’s capabilities as MCP (Model Context Protocol) servers so that AI agents can reason over what C2A can do, choose the right action, and execute it — with the judgment and guardrails a security product demands. This comes in parallel to the internal use of AI as part of the R&D and product development process. We are hiring someone to lead product level and internal team AI end-to-end: from protocol and architecture decisions to server-side implementation to the AI logic that decides when and how our tools are used, to internal processes that improve R&D and product development efficiency. This is a hands-on position with managerial aspects, not an advisory role. You will be building hands on in parallel to building the process and managing/guiding the team.
C2A Security is the only context-driven product security company built to support organizations developing software-defined and AI-enabled products. Our global customers and partners include leaders such as Bayer, Elekta, BMW Group, Daimler Truck AG, Deloitte, Siemens, Valeo, Marelli, NTT Data, and Orcanos. We transform cybersecurity into a business value multiplier through automated security and compliance, reducing release times, cutting costs, and streamlining product development.
Founded in 2016 and headquartered in Jerusalem, Israel, C2A is led by Michael Dick, a veteran of NDS and Cisco. C2A offers a strong company culture, significant growth opportunities, and the chance to work with a diverse and talented team on impactful projects that shape the future of product cybersecurity.
Think you are a good fit? We would love to hear from you.
Dynamic threat modeling and risk assessment aligned with global regulations
LLM-agnostic generative AI layer powering automation across every module
Aggregated threat feed contextualized against your actual products
Generate, manage, and triage all BOMs and vulnerabilities across the lifecycle
Quantitative optimization of mitigation strategy and security control allocation
Configurable dashboards and reports across every EVSec data layer
Extract software composition and risk from firmware and binaries without source code
Optimized anomaly detection for Ethernet and CAN, plus ECU runtime protection
Quantify and manage cybersecurity risk for products operating in the field
Enrich SOC events with deep product and architecture context
Context-driven test and validation with intelligent fuzzing, integrated into CI/CD
AI-powered static analysis integrated into CI/CD with reduced false positives
Foundational layer: cyber model, workspaces, and integration backbone to DevOps toolchain
Out-of-the-box and customizable workflows for regulatory and security processes
Centralized compliance management with evidence generated from live data