Assuming this is FileVault (Apple's disk encryption) and you do not have the user's password (cannot get past the FileVault login), then your path to recovering the machine is to erase it and reinstall the OS. This will remove the encryption. Please note, all data will be lost. However, if you don't know the user's password, you will not be able to decrypt the drive and thus will not be able to get any data.
Next, if the user signed in to the device with a personal Apple ID and enabled Find My, then the device is activation locked to the ex-employee's Apple ID. If you have proof of purchase, you can open a request with Apple to remove the activation lock on the device by reviewing this KBase article.
Hope this helps. Please note, if you had an MDM and your enforced disk encryption through the MDM, you would have the recovery key and you would be able to access the device and the data. If you do not have an MDM, you likely should enable encryption and record the decrypt key manually. Note, without an MDM, as skilled user could disabled FileVault, discarding your known key, and then reenabled it which generates a new key. This would lock you out.
Hope this is helpful