I don't know as much about android as I do about Apple, but here are the basics:
- Keep the operating system up to date
- Remove unused apps
- Never grant permission to an app for anything it does not need, and periodically review the permissions your apps have
- Some malicious apps make it through Google (or Apple's) screening process, you're a bit less likely to have an issue with a well-known publisher or an app with a large number of positive reviews
- Back your device up religiously