SME - IT security
About this role
Job Summary
Job Description โ Mobile Security Engineer (Android & iOS) Location: Bristol, UK / Offshore Open Positions: 4 Duration: 12โ60 Months (Enduring Requirement) Engagement Model: Specialist Supplier Resource Augmentation Job Summary (150 Words) We are seeking experienced Mobile Security Engineers with strong expertise in Android and iOS application development and security to support a large-scale mobile engineering program. The role focuses on designing, developing, securing, and maintaining enterprise-grade mobile applications while ensuring compliance with security, regulatory, and governance standards. The successful candidate will work closely with product owners, architects, cybersecurity teams, infrastructure specialists, and delivery partners across UK and Offshore locations. You will be responsible for embedding security throughout the software development lifecycle, implementing secure coding practices, conducting vulnerability assessments, and supporting continuous improvement initiatives. The position requires hands-on experience with modern mobile development frameworks, authentication mechanisms, encryption techniques, and security testing tools. Candidates should be comfortable working within Agile delivery environments and collaborating across multiple stakeholders. This enduring requirement supports both immediate delivery needs and longer-term strategic capability development within the mobile technology landscape.
Key Responsibilities
Key Responsibilities (150 Words) Design, develop, test, and maintain secure Android and iOS mobile applications that align with business and technology objectives. Implement secure coding standards and ensure compliance with enterprise security policies throughout the development lifecycle. Conduct code reviews, threat modelling sessions, vulnerability assessments, penetration testing remediation, and security validation activities. Collaborate with cybersecurity teams to address security findings and proactively mitigate risks. Integrate authentication, authorization, encryption, certificate management, and secure API communication mechanisms into mobile solutions. Support CI/CD pipelines and automate security controls within delivery processes. Monitor application performance, security posture, and operational stability across production environments. Participate in Agile ceremonies, sprint planning, backlog refinement, and technical design discussions. Produce technical documentation, security artefacts, and operational runbooks as required. Work effectively with UK and Offshore stakeholders, suppliers, and engineering teams to deliver high-quality, secure mobile solutions while contributing to architecture reviews and technology roadmaps.
Skill Requirements
Skill Requirement (150 Words) Strong experience developing native Android applications using Kotlin and Java, and native iOS applications using Swift and Objective-C. Deep understanding of mobile application security principles, including OWASP Mobile Top 10, secure coding practices, threat modelling, and vulnerability management. Hands-on experience implementing authentication mechanisms such as OAuth 2.0, OpenID Connect, MFA, biometrics, and certificate-based authentication. Expertise in encryption technologies, secure key storage, token management, and transport layer security. Experience with mobile app hardening techniques, reverse engineering protection, jailbreak/root detection, and secure API integrations. Knowledge of static and dynamic application security testing tools, mobile security frameworks, and vulnerability scanning solutions. Familiarity with CI/CD pipelines, Git-based source control, automated testing, and DevSecOps practices. Strong troubleshooting, debugging, and performance optimization capabilities. Experience working within Agile delivery teams and enterprise-scale environments is essential for success in this role. Other Requirement (150 Words) Candidates should possess excellent communication and stakeholder management skills, with the ability to collaborate effectively across geographically distributed teams and suppliers. Experience working in highly regulated industries such as banking, financial services, insurance, telecommunications, or government sectors is highly desirable. Strong analytical, problem-solving, and decision-making capabilities are required, alongside the ability to manage competing priorities in a fast-paced environment. The role requires participation in architecture reviews, governance forums, security assessments, and technical workshops. Candidates should demonstrate a proactive approach to risk identification, issue resolution, and continuous improvement initiatives. Familiarity with cloud platforms, enterprise integration patterns, API ecosystems, and modern software engineering practices will be advantageous. Relevant certifications in mobile development, cybersecurity, cloud technologies, or secure software engineering are preferred. Flexibility to work with UK and Offshore teams and support critical delivery milestones is essential for successful engagement.
Other Requirements
Additional Request (Job Description) (150 Words) This requirement supports four specialist Mobile Security Engineering positions based across Bristol, UK and Offshore delivery locations. The initial strategy is to fulfil these roles through specialist suppliers in the short to medium term while simultaneously evaluating the capability and maturity of strategic technology partners to support future demand. Resources will be expected to provide immediate value within ongoing mobile initiatives while contributing to sustainable knowledge transfer and capability development. Successful candidates must demonstrate a proven track record in secure Android and iOS engineering, security-first design principles, and enterprise-scale delivery. The engagement is expected to last between 12 and 60 months, reflecting a long-term and enduring demand profile. Individuals should be capable of operating independently, mentoring junior engineers where appropriate, and collaborating with multidisciplinary teams to deliver secure, resilient, and scalable mobile solutions that meet business objectives, security expectations, and customer experience standards.
Frequently Asked Questions
Is the salary disclosed for the SME - IT security position at HCLTech?
Where is the SME - IT security position at HCLTech located?
How do I apply for the SME - IT security position at HCLTech?
When was the SME - IT security job at HCLTech posted?
You'll be redirected to HCLTech's official application page on successfactors.