Absolutely, to begin with you could select your fiber to be the primary path for all traffic. The VSAT link could sit on the other WAN port but through settings in Security Appliance > Traffic Shaping, be told to only ever pass traffic when your fiber is down.
You'd have to get Meraki Support or your Meraki SE to enable this - but we can enable functionality where when failing over to your other WAN path we can enable the use of the cellular firewall rules you define that those page. This means you could have additional firewall rules enforced when you start using your VSAT path. IE. to block out non-critical VLANs, backups, etc.