Skip to content
CISO Spotlights

Career profile

Thomas Hill

Chief Information Security Officer, Candescent

Status
Current role, per sources checked 9 June 2026
Appointed
June 2026
Published

Compiled 5 October 2026 from public records. Each statement below is drawn from the sources listed at the end.

Thomas Hill is the Chief Information Security Officer of Candescent, appointed in June 2026. Candescent describes itself as a company defining the era of Intelligent Banking for banks and credit unions, serving more than 1,300 banks and credit unions.

Career path

Hill's security grounding began in the Air Force, which he joined at eighteen, before he moved into IT roles where he also served as a security officer and later led a data center. He went on to serve as CIO and CISO at Live Oak Bank, where he led technology risk management and security operations and oversaw the bank's shift to a cloud-defined operating model.
That cloud-first strategy earned the bank the 2018 BAI Global Innovation Award.
While at Live Oak Bank he discussed cloud security provider selection and multicloud challenges with Orca Security's chief executive in a recorded interview. He holds a Bachelor of Science in business administration and an MBA with a concentration in management of information systems and security from Saint Leo University, along with CISSP, CISM and CIPT certifications.
Hill served five years as CISO at nCino, a cloud banking company, where he built and scaled enterprise-grade security programs supporting 1,850 financial institutions globally and led incident response and governance through phases of rapid corporate scaling and public market scrutiny.
At Candescent, he leads information security initiatives for the company's Intelligent Banking Platform, including risk-based governance frameworks addressing SEC cybersecurity disclosures, SOC 2 compliance, and emerging standards such as the NIST AI Risk Management Framework and Cloud Security Alliance guidance.

Public talks and commentary

"Banks and credit unions are operating in an increasingly complex threat environment, particularly as fraud tactics become more sophisticated and AI expands the attack surface," said Hill. He has presented on Cybersecurity Leader's Guide to Developing an Adversarial Mindset at the University of North Carolina Wilmington's cybersecurity track, part of his continued work with the university on building resilient careers in cybersecurity.
In an earlier interview, Hill described leadership as distinct from management and argued that pairing a CISO with a CIO as equal partners, rather than placing security under IT, produces stronger risk outcomes for a bank.

Sources

  1. 1.
    candescent.comcandescent.com · published 9 June 2026 · checked 5 October 2026 · tier A
  2. 2.
    csbapp.uncw.educsbapp.uncw.edu · undated page · checked 5 October 2026 · tier A
  3. 3.
    bankinfosecurity.combankinfosecurity.com · published 24 January 2021 · checked 5 October 2026 · tier B
  4. 4.
    Cybersecuritytechtarget.com · published 1 February 2019 · checked 5 October 2026 · tier B
  5. 5.
    govinfosecurity.comgovinfosecurity.com · undated page · checked 5 October 2026 · tier B

Tier A: the organization itself, a regulator or a government page. Tier B: established trade or business press.