Stewart
It depends also on how many apps you plan to run. If you have lots it makes more sense to manage them through Sandboxed Google Play for prompt regular updates. Updates after all are prob the most important thing to keeping a device secure. (thanks GOS!)
You also have the option to run a separate profile of course for Sandboxed Google, then in the owner profile you could have for example Signal from their website/Mullvad VPN from their website/Standard Notes from their website etc etc. Those are just examples of some open source apps that are respected on this forum, its your choice at the end of the day. I know though that people often run different profiles for a while and find its too inconvenient. Anyhow hope that helps a bit.