Will Spencer

Business Information Security Officer (BISO) @ Altria | Global Security Strategy & GRC | M&A Integration ($2B+) | Enabling Business Growth via Secure Cloud & AI | Team Leadership

Role
Business Information Security Officer at Altria
Location
Richmond, VA, US
LinkedIn followers
500 followers
Information TechnologyView LinkedIn profile

About Will Spencer

Strategic Visionary & Leader | Global Cybersecurity | Revenue EnablementI build business value by aligning security strategy with commercial velocity.I am an accomplished cybersecurity executive with a track record of bridging the gap between technical risk and commercial strategy. While many leaders focus on \"Audit Readiness,\" I focus on \"Business Readiness\"—ensuring that innovation, from AI adoption to Global M&A, happens safely and at speed.As BISO at Altria and formerly as a Crisis Leader in healthcare, I have led high-performing teams to protect multi-billion dollar portfolios without slowing operational velocity.The Strategic Value I Deliver:Enabling Revenue: Architected the security framework for a cloud-based Data Lake, enabling the business to model data for ~$500M in projected future value.Global Governance: Directing security strategy for complex international business units (UK/Sweden), executing GDPR Data Transfer Agreements to protect cross-border investments.M&A Execution: Led security diligence and integration for the $2.3B acquisition of NJOY, ensuring 100% remediation of technical debt to preserve deal value.Operational Resilience: Directed BCM and Incident Response for critical infrastructure, ensuring 99.9% availability during high-stakes digital transformations.I am a strategic thinker with a hands-on approach, driving comprehensive security programs that allow the business to say \"Yes\" to innovation.Core Competencies: Revenue Enablement | AI Governance & Safety | Mergers & Acquisitions (M&A)| DevSecOps & Product Security | Crisis Management & Resilience

Experience

  1. Business Information Security Officer

    Altria

    Jun 2020 — Present · Richmond, VA, US

    Strategic Leadership: Strategic BISO for Digital Marketing, Distribution (AGDC) & International Sales ($1M+ budget). Primary risk advisor presenting to C-Suite, aligning security investment with commercial growth strategies, moving security from blocker to business enabler.COMMERCIAL & REVENUE ENABLEMENT$500M+ Value: Led cross-functional team for \"High Confidential\" Azure Data Lake, enabling analytics teams to ingest sensitive data for ~$500M in projected future revenue.AI/Sales Velocity: Secured deployment of AI-driven Digital Adoption Platforms (Brainshark/WalkMe), accelerating Field Sales training & execution.Platform Scaling: Secured Salesforce CG and Experience Cloud rollout, protecting partners & B2B portals.STRATEGY, M&A & THREAT MANAGEMENT$2.3B M&A Execution: Led security integration for $2.3B NJOY acquisition. Preserved deal value by identifying key risks pre-integration.Nuvona VTM Leadership: Directed Vulnerability Mgmt for Nuvona. Eradicated inherited technical debt by 70% via remediation sprints & monitoring.Global Governance: Directed strategy for UK/Sweden centers (Helix/Raa), executing DTAs and policy dev. for GDPR compliance & ISO alignment.EXECUTIVE PRESENTATIONS & GOVERNANCEStrategic Influence: Presented Annual Security Strategy roadmaps to LOB Execs, successfully securing budget. Delivered Quarterly Board & SOX Executive Reporting to guide risk investment.Leadership: Led hybrid org (Direct + Managed Service analysts) & delivered enterprise-wide awareness presentations, shifting culture to resilience.Supply Chain: Managed TPRM (300+ vendors), consolidating for $6M in projected savings.PRODUCT SECURITY & DEVSECOPSCI/CD Security: Managed risk in dedicated pipelines (.NET/Apex) for external sites (AGDCNow, Salesforce), enforcing \"Quality Gates\" to block high-risk vulnerabilities.Secure Code: Mandated DevSecOps (SAST/DAST) via Veracode/Code.scan to ensure regulatory compliance without slowing release velocity.

Education

  • Ohio Valley University

    Bachelor of Arts - BA, Business Administration, Management and Operations

    2004 — 2007

  • Virginia Commonwealth University - School of Business

    Master’s of Science, Information Technology

    2017 — 2018

  • Ohio Valley University

    Bachelor of Science, Information Technology

    2004 — 2007

Skills

  • Hipaa
  • Troubleshooting
  • Vsphere
  • Vendor Management
  • System Administration
  • Security
  • Security Operations
  • Risk Management
  • Disaster Response
  • Windows 7
  • Incident Management
  • Active Directory
  • Xp
  • Windows Server
  • Windows Server 2012
  • Backup Exec
  • Critical Incident Response
  • Security Audits
  • Servers
  • Project Management
  • Windows Server 2003
  • Security Incident Response
  • Emergency Management
  • Vmware
  • IT Governance
  • Firewalls
  • Windows Server 2008
  • Management
  • Group Policy
  • Change Management
  • Visio
  • Disaster Recovery
  • Windows
  • Vmware Esx
  • Network Security
  • Software Documentation
  • Incident Response

Find verified contacts for anyone on LinkedIn

Unifers gives sales teams verified emails and direct dials, enriched profiles, and outreach that lands in the inbox.

Free plan included · No credit card required

This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.

Will Spencer — Business Information Security Officer at Altria in Richmond, VA, US | Unifers