Paul Rudd did it better
Add to this periodic CIS benchmark with OpenSCAP to diagnose any openings and certain types of vulnerabilities as you add additional software or make configuration changes. Hardening your OS is a tough task, but even with windows or macOS, you can run into vulnerabilities that are completely there from bad configuration or rouge software.
Now that I have that out of the way, it doesn’t matter what OS you run, there will be vulnerabilities. Being diligent in updating your machine (both the os and installed software) will do a lot of good to keep your workstation safer.