The sad fact of the matter is that we cannot trust individuals that have ever worked with these agencies, nor with the private contractors that supply them. The risk of insider attacks is too high. Equally, we cannot trust companies that employ those individuals.
If silicon valley is to recover the confidence of it's customers, it must go through the painful and heart-rending exercise of dismissing all employees with any connection whatsoever to government espionage. Many innocent people will lose their jobs, and will face the prospect of being excluded from high-tech employment in the private sector, but I cannot see any other way of regaining trust in our fundamental infrastructure.
Wouldn't it be the people that used to be blackhat and have transitioned to gray or white-hat hacking that would be the best people to provide their services for pen-testing/anti-virus writing/etc?
Is the probability of an so-called ex-virus-writer writing in exploits into the system higher than someone else?
Is their knowledge worth the chance?
Without trust, the antivirus vendor has no business whatsoever. As a result, they are (or jolly well should be) ultra-careful to earn that trust. This includes subjecting their employees to a certain degree of vetting.
In the age of cloud computing, the same relationship dynamics are observed between businesses and the cloud vendors to whom they entrust their data.
See? There it is again: Trust.
Important stuff.
From our parent: I used to work in the antivirus industry, and, as I recall, anything that even hinted at a history of hacking or virus-writing would lead to instant dismissal and black-listing (from pretty much the entire computer security industry). I imagine that the same prohibition would now apply to former government employees also.
They used the world "hacking", which I took to mean any form of hacking. We'd need the parent to respond to which one was meant, of course; but if it means any sort of hacking, from xbox modding to submitting bug and exploit reports to Google (which, how do you know if there's an exploit without trying to find it?), then hacking would include all of those people, including the people who you define as "ethical hackers".
If you're a known, aggressive and clearly unreformed cyber-saboteur, then it's pretty much a given that you shouldn't be hired to an anti-virus company since you probably are in there to commit insider attacks (I can't know for sure, I'm not in your brain) and it's reasonable to not hire you; however, if you're a tinkerer and inspector of things and dismantler of technology, then you would know how systems work and where issues are and could even be an asset, especially if you're very good at it. Depending on the author, both of those people could be seen as 'hackers'.
A number of notable, convicted hackers have done additional work (whether employment or successful entrepreneurship or both) in the computer industry (in security-related or other subfields) after conviction. Kevin Mitnick, Julian Assange -- long before WikiLeaks -- and YC's cofounder Robert Tappan Morris are among the more notable examples.
Having a spouse, kids, and a nice house in a nice neighbourhood makes any kind of anti-social behaviour that much harder to justify from a purely pragmatic, never mind ethical point of view.
I.e. young men often have nothing much to lose and act accordingly.
I'm not sure where you got that from. A large percentage of the security industry is made up of people who got their start as blackhats.
This is unfortunate--in a just world everyone doing this would be imprisoned for many years and have all their ill-gotten gains stripped from them--but a real fact. And the typical NSA software developer is certainly highly qualified and very, very smart. Going purely by business concerns, if you have a need for someone with the skill set that'd come from working for the NSA, you can't afford to pass them up just because they worked with the NSA.
You can also be sure that, even if the NSA were disbanded fully and all its employees hated so much that they could not get domestic employment anywhere, many international actors would be extremely excited to pay top dollar for their talent. And by top dollar, we're not talking piddling six figure salaries.
Now, if they decided they wanted out, well ... good luck with that in the manner you describe. I suspect that it won't be too hard, though. They deal with "Big Data" problems at a scale that few do, so being an NSA engineer likely is bound to be a similarly prestigious resume line as working for Google. Aside from the working for an evil entity part, that is, but some employers will not care as much about that.
Sometimes employers are willing to take that risk.
Do you think Ed Snowden is now more or less employable now?