Yoast SEO: Yoast SEO is most popular plugin for SEO in wordpress website. They take care of almost everything which is important for your website. you can also generate sitemap, set page meta title, meta description etc.
Change login url. By default it is /wp-admin or /wp-login.php. you can make it anything (which hackers might not guess).
change admin user name (change it to something else to avoid brute force attack)
W3 Total Cache: There are various cache plugins available out there. You can any of top rated. They are very necessary for speed optimization. Make sure you enable at least:
optionally enable page/object cache.
EWWW Image Optimizer: This plugin will automatically optimize new images that you upload, it can also optimize all the images that you have already uploaded, and optionally convert your images to the best file format. You can choose pixel perfect compression or high compression options that are visually lossless. Most important feature of this plugin is that it can compress and convert images to Next-Gen format ( WebP, JPEG 2000, JPEG XR ) which are recommended by google page speed insight. To enable WebP and other Next gen format make sure to enable below options. You can access all these options from plugin settings page.