Richmond’s cybersecurity community is unusually well organized. The Virginia Cyber Security Partnership, founded by Dominion Energy and the Richmond FBI in 2012, counts two of the leaders below among its board and advisory members. Several more sit on federal advisory councils, university boards, and industry working groups that meet regularly in and around the city. What follows is a look at the CISOs running security at some of the largest organizations headquartered here, from a Fortune 500 tobacco company to the Federal Reserve System.
Chas Heng – CISO, Altria
Chas Heng owns a Burn Boot Camp franchise in Richmond’s Libbie Mill neighborhood, voted the city’s best gym in 2025. He runs it alongside his day job protecting a Fortune 500 company. Heng began his career as a network security administrator at Broughton Systems, then spent more than 17 years at Capital One in roles covering enterprise infrastructure delivery, technology and security integration, and information security risk management. He joined Altria in October 2018 as Deputy CISO and became CISO in March 2020. He has presented to Altria’s Board of Directors and advised multiple board committees. Heng received the Executive Women’s Forum Catalyst Award in 2021 and serves as an Executive Ambassador for that organization, sits on IBM Security’s Board of Advisors and the Gartner Research Board, and belongs to the FBI’s Domestic Security Alliance Council. He previously advised Tech For Troops, a Richmond nonprofit that provides computers and IT workforce training to veterans.
Jason Ancarrow – CISO & VP Technology, CarMax
Jason Ancarrow has led CarMax through attempted ransomware and extortion, nation-state intrusion, supply chain compromise, and AI-accelerated social engineering. His view is that resilience, not prevention alone, is what marks a mature program. He spent nine years at Capital One as an information security program manager and then Director of Information Security and Risk Management, followed by a year with IBM’s Global Security Services practice. Ancarrow became CarMax’s CISO and VP of Technology in June 2016, a role he has now held for more than a decade. His current focus includes securing enterprise and agentic AI, non-human identity governance, and post-quantum readiness. He organizes RVATech’s annual CyberConVA conference and hosts its CISO Roundtable as an advisory board member of the Virginia Cyber Security Partnership. He also serves on advisory boards at Virginia Commonwealth University’s Cybersecurity Center and Virginia Military Institute’s Computer Science Department.
Sean Stalzer – CISO & VP of Cyber Security, Dominion Energy
Before networks were common, Sean Stalzer wrote some of the initial algorithms that taught a computer to tell a tank from a truck from a civilian car. That work, done during four and a half years of internships with the US Army, became part of the foundation for modern smart weapons technology. He also ran computer systems for weapons tests in an era when taking computers into the field was a new experience. Stalzer now serves as CISO and Vice President of Cyber Security at Dominion Energy, where he designed and implemented a converged cyber and physical security organization. He has built collaborative information-sharing relationships with US government partners, and the company’s annual Cyber Fortress exercise stands as an example of public-private partnership in the sector. He sits on the Executive Leadership Team of the FBI and DHS Domestic Security Alliance Council, which brings together more than 750 large US-owned companies, and previously chaired its Threat and Resilience Information Sharing Committee. Stalzer is a founding advisory board member of the South Carolina Critical Infrastructure Cybersecurity Program, serves on the Utah Governor’s Cybersecurity Commission board, and sits on the governance committee of CRISP, a Department of Energy partnership Dominion helped establish to build collective defense across peer utilities. He also serves on the boards of The Cyber Guild and the Virginia Cyber Security Partnership.
Tammy Hornsby-Fink – EVP & CISO, Federal Reserve System
Tammy Hornsby-Fink spent nine years in the United States Air Force as a communications computer systems specialist. She then worked as an installer, implementation engineer, and network engineering manager before co-founding an IT consulting practice in the Dallas-Fort Worth area. Hornsby-Fink joined the Federal Reserve System in 2003 as a network engineer and has spent 23 years there. She advanced through network engineering management and an assistant vice presidency covering enterprise network services, then served nearly four years as Vice President of Information Security. Two years as Vice President of Payment Security followed, where she worked on the Strategies for Improving the U.S. Payment System. She became Senior Vice President and Deputy CISO in 2018 and has served as Executive Vice President and CISO since October 2019, responsible for the Federal Reserve’s information security policies, architecture, programs, and incident response team. She also spent six years on the board of United Way of Greater Richmond and Petersburg.
Dan Han – CISO, Virginia Commonwealth University
Dan Han won the SANS Python NetWars capture-the-flag competition in 2018 and placed third in the SANS public cloud security Cloud Wars CTF in 2021. He has worked at Virginia Commonwealth University for nearly 25 years, starting in 2002 as an IT manager supporting academic computing for students and faculty in the School of Medicine. He became the school’s Manager of Information Security and Infrastructure Services in 2008, building a comprehensive security framework covering internal policies, business continuity, and disaster recovery. Han has served as the university’s CISO since March 2011, providing oversight to the information security management program at one of the largest universities in Virginia. During his earlier years he also consulted for two local dental practices, virtualizing servers and reducing one company’s annual operations overhead by more than 18%. He holds CISSP certification along with four GIAC credentials, and he has taught as an adjunct professor at VCU since 2022.
Glendon Schmitz – CISO, Cherry Bekaert
Nearly 13 years in the United States Air Force gave Glendon Schmitz his foundation. As Director of Cyber Defense at Joint Base Elmendorf-Richardson, he established the first Air Force cyber defense operations in Alaska and expanded cyber defense tactics across 70 Air Force installations. He then launched the first cybersecurity and due diligence programs for Northrim Bank, covering 18 branches and two mortgage brokerages, where he identified and eliminated more than 3,000 critical vulnerabilities. Schmitz spent nearly six years as CISO of the Virginia Department of Behavioral Health and Developmental Services, protecting 12,000 patient records while building a DevSecOps program that served 12 hospitals and cut incident response time by 30%. He served ten months as Chief Information Security and Privacy Officer for the Virginia State Corporation Commission, leading zero-trust adoption and establishing a privacy program for the Commonwealth’s regulatory operations. He became CISO of Cherry Bekaert in August 2026.
John Thompson – CISO & VP of Infrastructure and IT Operations, Landstar
John Thompson spent his first decade in security-adjacent roles that were really about scale. At Advance Auto Parts he led enterprise solution development for a $9 billion retailer with more than 6,000 stores and 74,000 employees, managing 90 employees and 80 contractors. Earlier there, as IT Director for Supply Chain Development, he cut system outages by 40% and implemented a voice-directed picking solution that reduced picking labor by 10% and errors by 50%. He also led an Oracle Retail Management System implementation that Oracle recognized with a 2011 Outstanding Achievement in Business Performance Award. Thompson moved into security leadership at LHC Group, serving as SVP and CIO/CISO and then SVP CISO, where he built the cyber security strategy and team around NIST 800-53. He spent three and a half years as CISO of LL Flooring in Richmond before joining Landstar in June 2025 as CISO and VP of Infrastructure and IT Operations. His career began as an architecture manager at Accenture, working with insurance clients including USAA, Farmers, and Erie.
A City That Builds Its Own Institutions
Richmond’s security leaders do not just hold jobs here. They build the structures that hold the community together. Stalzer helped found the Virginia Cyber Security Partnership through Dominion Energy, and Ancarrow now sits on its advisory board while running the conference and CISO roundtable that grew out of it. Han teaches at VCU, whose Cybersecurity Center advisory board includes Ancarrow. Heng advised a local nonprofit training veterans for IT careers, and Hornsby-Fink spent six years on the board of the region’s United Way. Schmitz and Thompson brought institutional experience from the Air Force, community banking, state government, and national retail into the mix. The result is a security community whose members keep showing up in each other’s rooms, which tends to make a city’s defenses stronger than the sum of its companies.
Discover more CISOs securing their organizations:
- From the Plains: Wichita’s Cybersecurity Leaders to Watch
- Oklahoma City’s Cybersecurity Leaders to Watch
- From the Tennessee Valley: Knoxville’s Cybersecurity Leaders to Watch
- Buffalo’s Cybersecurity Leaders to Watch
- Cleveland’s Cybersecurity Leadership Bench
John Kevin Hao is a news and feature writer covering cybersecurity, technology, and business targeted for professional audiences.

