Requiring a pin means no one can use your fingerprint or your face to unlock your device.
An NSA agent recommended restarting your phone every week. This can potentially clear out malware that doesn't have permissions to start after a reboot.
I hope a consistent, user-friendly alternative that works on all Android phones arrives soon. I've tried so many with an old phone and they're always a pain to install and then don't work quite right. I also don't want to spend $500USD for a phone designed specifically to sidestep Android.
It would help if Android/Google didn't consistently try to block every single thing that would allow you to get rid of Android, but they're never going to allow that.
I hope that something user-friendly and consistent arrives soon. I will ditch Android in a second when that happens.
While I agree with most of the things you said, automatic reboots is a good security feature. And it isn't android that's the problem. It's Google Play Services.
It would help if Android/Google didn't consistently try to block every single thing that would allow you to get rid of Android
If you're referring to bootloader unlock, that's not really anything to do with Android, that's to do with carriers and manufacturers. The first-party devices don't have that.
I don't think that Pixels (made by Google) are designed to sidestep Android ;). Unfortunately, what you're asking can't really be done because of the vast hardware incompatibilities between brands of Android phones and between generations of them.
The best privacy option ironically seems to be GrapheneOS, which runs on Pixels, as alluded to above. You can get older Pixels pretty cheap. They aren't my favorite phones but I sometimes consider doing that.