Dont use (only) fingerprint to unlock, AS they can force you to put your finger, they can't force you to remember a password.
If possible have only Foss apps on your main profile (fdroid, neo store etc.) And one/multiple separate profile for closed source apps if you need them.
Check the tools under "security and privacy" in your pull down menu (like hardened memory allocation)
Inform yourself on what a secure system helps you with, and what not. (For example they can still hijack cellphone towers (stingray attack) and act accordingly