you should be running updates regardless of a user bothering you. You want a simple form of intrustion detection. Anti-virus should be a given this day and age, but something like Norton Personal Firewall, etc..... can be used if used correctly. A router with access-lists would serve your a great purpose, but you probably aren't in an environment that would require that drastic measure.
Just install a commercial firewall software and then lock it down, many default configurations on commercial products have their own exploits. Be sure to research comments on the software and pre-cautions that are noted from people who have used it.
But again, a simple software firewall shouldn't be a problem. For real protection, in conjunction with IDS, you can just pull the network cable from it when you are't sitting there. This will prevent whomever from accessing the machine in your absence.
Remember that the only security is physical security. Isolation, when possible.