The major points of vulnerability nowadays are the browser and the user. Secure the shit out of your browser - aggressive adblock, disable/click-to-play all plugins, no unnecessary addons. As a user, educate yourself about the realistic threats. Download software from reputable places - if you're used to a Linux package manager, this will take some adjusting but it's not difficult. When you're installing something, actually read what it's doing and think, don't just click next excitedly. I shouldn't even have to say this, but don't open email attachments unless they're from someone you know and you're expecting exactly what they sent. Let Windows install updates automatically and reboot when it asks. Keep your other software up to date - something like Chocolatey (https://chocolatey.org) might help, but that has its own security upsides and downsides. Turn on Windows Defender and let it keep itself updated.
Windows firewall is a pain in the ass, but if you have some time you can lock stuff down quite a bit (Windows Firewall Notifier).
Personally, I don't run an antivirus at all; I got sick of Windows Defender making disk accesses so slow so I disabled it. At most I'd set up scheduled scans.
Turning on controlled folder access if you're paranoid about ransomware. Not much else really. I haven't noticed any viruses / slowdowns / malfunctions this way.
Don't install antiviruses, they're basically malware created to fight malware. Windows defender in Windows 10 is enough.
Keep your device updated.