yes it can work, point the LMS IP in the ap system profile to the public IP with 500+4500 UDP port-forwarded to the local controller.
I am not sure how much benefit you get from the local controller if the authentication back end for the eap-tls is back in corp in Singapore, if the auth traffic has to go to Singapore, maybe the APs will be happy enough running from Singapore too.
Just watch out that bridge mode is a bit unloved (not just from unsupported features perspective but also 'features that work in Instant but don't exist in bridge mode (e.g. DPI related things)'
And watch out for limitations like "no more than 32 aps on the lan" so that the firewall state can sync during ap to ap roaming (which doesn't work well if the bridge VAP is also using route src-nat).
Try to avoid using src-nat for the bridge virtual APs if you have any sort of roaming happening at the site(s), not just for the above mentioned issue but also because there is no nat anchor and you will get session breakage on roaming. Better to use another device above the APs as the NAT device (e.g. a capable L3 switch or the broadband router that connects you to the Internet, but you need to take care of the dhcp and/or routing in that case)
Finally, going the RAP route can incur a heavier provisioning overhead - unless your using the newfangled unified APs or "real RAPs" not just campus APs reprovisioned as RAP (thus requiring console port provisioning or local lan access to a controller at least once to provisoning before sending to site).
These are just some random thoughts, there are a few ways to skin this cat, I am sure you will get some other thoughts about it - including a few reminders to use instant :)