The guy's job was apparently to check out profiles of people that may present a security threat. So if his job was to look at profile data all day, in this specific case his firing would almost have to be reactionary, because his nefarious activities would have looked like normal job activity to any auditing program. We only know his activities were nefarious because he said so. A developer or people in almost any other position for that matter would likely have been caught proactively.