You don't need to change the passwords if you don't install OpenSSH. Removing OpenSSH removes any necessity to change the password. In both cases, because OpenSSH is not installed there is no route to the device. Because there is no route to the device it's not possible to hack via OpenSSH (because OpenSSH is not present).
As far as other security features: iCaughtU Pro, PLS Recovery are two I can name off the top of my head. Activator, used to disable a long press of the hold button on the lockscreen (so the phone can't be shut off) works too. There's also a tweak that lets you set a passcode/password to open apps.
I'm not sure if any of those work on iOS 9 yet however.