As far as I am aware if you create another bridge but do not assign it an interface / IP address and then connect the VMs to that bridge and setup that bridge on the pfsense VM as well.
For my setup, I have pfsense running in a VM and have trunked 4-gigabit network ports together to a switch and then there are 3 other gigabit network parts dedicated to the VMs on that same host for them to access the PFSense VM and ultimately the internet. I did this as I have multiple nodes and allowed me to setup the same configuration on all nodes and adds the VMs to the network so other devices on the LAN can access them, in fairness I did not test using a private network for the VMs that was internal to a host and then using pfsense to manage traffic for the VMs.