Writing a malicious code as a security consultant.

          As the CEO of an organization, you just learned that the IT security department hired a convicted hacker that used to write malicious code as a security consultant. Would you overturn this decision? Why, or why not?