SME - IT security
United Kingdom
Job Description
SME - IT security
Bristol, England

Job Summary

Job Description – Mobile Security Engineer (Android & iOS) Location: Bristol, UK / Offshore Open Positions: 4 Duration: 12–60 Months (Enduring Requirement) Engagement Model: Specialist Supplier Resource Augmentation Job Summary (150 Words) We are seeking experienced Mobile Security Engineers with strong expertise in Android and iOS application development and security to support a large-scale mobile engineering program. The role focuses on designing, developing, securing, and maintaining enterprise-grade mobile applications while ensuring compliance with security, regulatory, and governance standards. The successful candidate will work closely with product owners, architects, cybersecurity teams, infrastructure specialists, and delivery partners across UK and Offshore locations. You will be responsible for embedding security throughout the software development lifecycle, implementing secure coding practices, conducting vulnerability assessments, and supporting continuous improvement initiatives. The position requires hands-on experience with modern mobile development frameworks, authentication mechanisms, encryption techniques, and security testing tools. Candidates should be comfortable working within Agile delivery environments and collaborating across multiple stakeholders. This enduring requirement supports both immediate delivery needs and longer-term strategic capability development within the mobile technology landscape.

Key Responsibilities

Key Responsibilities (150 Words) Design, develop, test, and maintain secure Android and iOS mobile applications that align with business and technology objectives. Implement secure coding standards and ensure compliance with enterprise security policies throughout the development lifecycle. Conduct code reviews, threat modelling sessions, vulnerability assessments, penetration testing remediation, and security validation activities. Collaborate with cybersecurity teams to address security findings and proactively mitigate risks. Integrate authentication, authorization, encryption, certificate management, and secure API communication mechanisms into mobile solutions. Support CI/CD pipelines and automate security controls within delivery processes. Monitor application performance, security posture, and operational stability across production environments. Participate in Agile ceremonies, sprint planning, backlog refinement, and technical design discussions. Produce technical documentation, security artefacts, and operational runbooks as required. Work effectively with UK and Offshore stakeholders, suppliers, and engineering teams to deliver high-quality, secure mobile solutions while contributing to architecture reviews and technology roadmaps.

Skill Requirements

Skill Requirement (150 Words) Strong experience developing native Android applications using Kotlin and Java, and native iOS applications using Swift and Objective-C. Deep understanding of mobile application security principles, including OWASP Mobile Top 10, secure coding practices, threat modelling, and vulnerability management. Hands-on experience implementing authentication mechanisms such as OAuth 2.0, OpenID Connect, MFA, biometrics, and certificate-based authentication. Expertise in encryption technologies, secure key storage, token management, and transport layer security. Experience with mobile app hardening techniques, reverse engineering protection, jailbreak/root detection, and secure API integrations. Knowledge of static and dynamic application security testing tools, mobile security frameworks, and vulnerability scanning solutions. Familiarity with CI/CD pipelines, Git-based source control, automated testing, and DevSecOps practices. Strong troubleshooting, debugging, and performance optimization capabilities. Experience working within Agile delivery teams and enterprise-scale environments is essential for success in this role. Other Requirement (150 Words) Candidates should possess excellent communication and stakeholder management skills, with the ability to collaborate effectively across geographically distributed teams and suppliers. Experience working in highly regulated industries such as banking, financial services, insurance, telecommunications, or government sectors is highly desirable. Strong analytical, problem-solving, and decision-making capabilities are required, alongside the ability to manage competing priorities in a fast-paced environment. The role requires participation in architecture reviews, governance forums, security assessments, and technical workshops. Candidates should demonstrate a proactive approach to risk identification, issue resolution, and continuous improvement initiatives. Familiarity with cloud platforms, enterprise integration patterns, API ecosystems, and modern software engineering practices will be advantageous. Relevant certifications in mobile development, cybersecurity, cloud technologies, or secure software engineering are preferred. Flexibility to work with UK and Offshore teams and support critical delivery milestones is essential for successful engagement.

Other Requirements

Additional Request (Job Description) (150 Words) This requirement supports four specialist Mobile Security Engineering positions based across Bristol, UK and Offshore delivery locations. The initial strategy is to fulfil these roles through specialist suppliers in the short to medium term while simultaneously evaluating the capability and maturity of strategic technology partners to support future demand. Resources will be expected to provide immediate value within ongoing mobile initiatives while contributing to sustainable knowledge transfer and capability development. Successful candidates must demonstrate a proven track record in secure Android and iOS engineering, security-first design principles, and enterprise-scale delivery. The engagement is expected to last between 12 and 60 months, reflecting a long-term and enduring demand profile. Individuals should be capable of operating independently, mentoring junior engineers where appropriate, and collaborating with multidisciplinary teams to deliver secure, resilient, and scalable mobile solutions that meet business objectives, security expectations, and customer experience standards

Information at a Glance

Why HCLTech?

At HCLTech, you'll supercharge your potential. You'll find your career. And you'll find your spark. All at a place that knows that helping its customers stay on top starts by putting its people first.

HCLTech is a global technology company, home to more than 223,000 people across 60 countries, delivering industry-leading capabilities centered around digital, engineering, cloud and AI, powered by a broad portfolio of technology services and products. We work with clients across all major verticals, providing industry solutions for Financial Services, Manufacturing, Life Sciences and Healthcare, Technology and Services, Telecom and Media, Retail and CPG, and Public Services. Consolidated revenues as of 12 months ending June 2026 totaled $14.8 billion.