I have not tried that, but I think the answer is no. That would give the cameras a direct route to the internet via the POE switch connected to the RP to the internet. You would connect your BI computer via the primary NIC to the RP. You might investigate putting your ISP supplied router in bypass mode and getting a router with built in OpenVPN.
What I have done to solve this issue is the following: My BI server is upstairs. My main PC that I use daily is in my office downstairs. This PC has two RJ45 jacks on the motherboard which I configured one for my main LAN and the other on the same subnet as the POE switches and cameras. That second connection goes to one of my POE switches. So I have access to each camera from both machines.
So just to confirm, it's the cameras/PoE switch on NIC2 that shouldn't have ANY direct internet access, not the BlueIris machine that the cams feed in to? i.e. as per your picture, only the cams are isolated, the BlueIris machine itself is still fully connected to the internet via NIC1? Sorry for coming accross as silly, I've just never had to fully understand this stuff before and want to research first before I buy anything.
Also, if I were to make a Raspberry pi into a VPN using PiVPN, would it matter exactly where that device is connected to my home network? I assume that wherever it's connected it would need to have access to the Blue Iris machine via it's NIC 1?