looking at your screenshot, I'm assuming that vmbr0 is your outgoing address and that you're hosting PVE behind NAT already?
If you're wanting to install nethsecurity on vmbr0 and vmbr1 you already have the basics in PVE. I suspect that nethsecurity will allow you to choose what its WAN interface is (vmbr0 in this case) and what its LAN interface is (vmbr1 in this case). So when you create your VM, you need to ensure that you give it access to both vmbr0 and vmbr1 by adding 2 networks to it.
There's no need (that I can see) to do any more in PVE itself, I have similar setups running both pfSense and OPNSense firewalls.