These things are useful:
1. Bitninja to monitor
2. SonarQube for code reviews
3. SFTP with PGP encryption & 2FA, if possible have jump server
4. Keeping all keys separately and pulling it from other source
Undergoing the security audit is the most time consuming process.
At the same time, it forces you to follow the industry best practices.
When you are indie hacker & ramen profitable, you can't hire someone to do this, its not cost effective.