If you can log in as account xyz over SSH, and account xyz has permission to do anything with sudo, how is that more secure than letting root log in over SSH?
Assume your primary user account is called "user".
Set up a second account, whose password you want to be your sudo password. Let's call this account "admin".
In /etc/sudoers:
Defaults:user runas_default=admin
Defaults:user runaspw
Now, as "user", you can sudo -u root whoami
and you will be asked for "admin"'s password.The only downside is that "root" is no longer the default user to become, you have to explicitly specify it.