Serve cv and pdf files under a different hostname
Even if cookie is secured and in http only, it is still a good practice to serve content under a different hostname. See as example https://raw.githubusercontent.com/ which serve github content.
The idea is to explore and even implement it