Skip to content

Open nowPosted 115 days ago

Cybersecurity Engineer

dfo9 open roles

Where
Manila Philippines
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowCybersecurity Engineerdfo · Manila Philippines
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on dfo's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.7%1 day
  2. 3.5%3 days
  3. 7.8%7 days
  4. 14.6%14 days
  5. 34.1%30 days
This job: posted 115 days ago

The posting

About the Role

We're hiring our first dedicated Cybersecurity Engineer to own the full security posture of a growing multi-vertical telehealth platform and EHR system handling Protected Health Information (PHI). This is a senior, hands-on build-and-maintain role — not a compliance checkbox or one-time audit. You'll embed security across our engineering culture, CI/CD pipeline, and GCP (Google Cloud Platform)-native cloud infrastructure, and keep us defensible as we scale across multiple healthcare verticals.

You'll serve as Sphere's first security hire, building the foundation ahead of a CISO (Chief Information Security Officer) joining in 2027. Everything you build should be documented, scalable, and transferable. You'll report directly to engineering leadership and partner closely with product and backend engineers daily.

Schedule: 9 AM to 6 PM EST

What You'll Own

  • Application & Cloud Security — Continuously assess and harden web apps, APIs, and GCP-native infrastructure; implement security controls across all environments and healthcare verticals
  • DevSecOps & Secure SDLC — Integrate security gates into the CI/CD pipeline: SAST/DAST, dependency scanning, secrets detection, container image scanning, and secure coding standards
  • HIPAA/HITECH Compliance — Maintain and improve our compliance posture including technical safeguards, access controls, audit logging, encryption standards, and BAA oversight; lay groundwork for HITRUST CSF certification
  • Vulnerability & Threat Management — Run ongoing vulnerability assessments, manage a risk register, triage findings, and drive remediation with engineering
  • Incident Response — Own the IR plan; lead detection, containment, and post-mortem for security incidents
  • Security Foundation Building — Document all security policies, controls, and architecture decisions to enable a smooth handoff to an incoming CISO in 2027
  • Security Culture — Be the go-to security resource for engineering and product — make PHI protection a default, not an afterthought

You're a Strong Fit If You Have

  • 5+ years of experience in application security, cloud security, or security engineering
  • Hands-on experience with DevSecOps tooling (e.g., Snyk, Trivy, Semgrep, GitHub Advanced Security, HashiCorp Vault, OWASP ZAP)
  • Strong GCP security fundamentals — GCP Security Command Center, Cloud Armor, Chronicle SIEM, VPC Service Controls, IAM, and Cloud Logging
  • Direct experience with HIPAA, HITECH, or comparable regulated environments (SOC 2, PCI-DSS, ISO 27001 a plus)
  • Proficiency in at least one scripting/automation language (Python, Bash, or similar)
  • Solid understanding of web application security (OWASP Top 10, API security, auth/authz patterns)
  • Ability to work independently and cross-functionally — you'll be the sole security voice for 12–18 months
  • Excellent written communication — able to document policies, explain risk to non-technical stakeholders, and write clear incident reports
  • Comfortable working with meaningful overlap with US Eastern or Pacific hours

Nice to Have

  • Security certifications: CISSP, CISM, CEH, Security+, GCP Professional Cloud Security Engineer, or equivalent
  • Familiarity with HITRUST CSF framework
  • Experience in healthcare tech, telehealth, or multi-vertical health platforms
  • Familiarity with FHIR/HL7 data standards and EHR security considerations
  • Experience conducting or managing third-party penetration tests
  • Exposure to Zero Trust architecture or SASE frameworks
From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against dfo's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on dfo's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    dfo's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.