My experience is that as soon as nested virtualisation is enabled, performance tanks. I needed this for docker on a windows dev VM.
If I'm reading your use case correctly, you maybe be better of creating a VLAN for your work VMS, and having all that traffic isolated on that VLAN and routed through the VPN.
This is also a reasonable advanced use case, but I think you will get a better result and more options for help with configuration that way.