Because of the cleartext-nature of nearly everything in RADIUS I would always send the traffic through a VPN tunnel. Sadly the Meraki-devices don't support RADIUS-DTLS. That could be natively terminated on the ISE.
For the VPN my first choice would be to integrate an AWS-vMX into autoVPN, but a traditional VPN would also do the job.