There are not as many sysadmin job these days because so many on-prem deployments have moved to the cloud. Consider becoming a cloud version of a sysadmin (whatever they’re calling it now…). Every platform offers lots of free learning resources and has a certification process.
After X attempts to log in, it bans the IP address.
It will scan your wordpress files and alert you if any of them have changed in suspicious ways (hacked).
It can disable the xml-rpc endpoint which is rarely used and is a big vector for hacking.
… and a lot more but those are the main ones for me.