We can spare ourselves the world's dumbest HN thread if we stipulate that by far the largest problem with Android is that it means a zillion different things. Campaign workers (or NGO employees) with "Android phones" are people that have every conceivable random phone that happens to be running some variant of Android.
In general my suggestion is people uninstall every app they don't "need" and to pay carefully attention to permissions.
Even when I was an iOS user, all I needed was a terminal, from ssh, emacs, gnus, screen, etc.
Who cares? Security conditional on expertise, extraordinary caution, and time investment is WORTHLESS.
Security is more about guiding (or forcing) human beings to the right behavior than it is about making technical mechanisms available for the willing and able. Your security model should assume that the user is stupid, grossly negligent, and in the case they are the employee or other agent of an organization, somewhat hostile to the interests of the organization.
At-risk nonspecialists should avoid all Android phones, and standardize on iPhones.
Does that mean that there are other specific Android phones that one could have required instead? Or are you keeping silent about the real reason?