Since LocalBitcoins holds a wallet, then anyone with my username and password has access to my funds. Until LocalBitcoins supports a two-factor authentication (2FA, e.g., Google Authenticator) I won't be using the site for any funds except for a trivial amount.
If you do add 2FA. also any withdrawal (send) would require an OTP to be entered. Others might want to see 2FA required on login as well, but at a minimum if I have 2FA enabled for my account then each withdrawal (send) should require an OTP.
I'm working on it right now.