I've used them for out of band management. In my country, the default APN gives you a private IP address, but you can just use a different APN to get a public IP address.
Are you sure there are no other APNs available that will give you a public IP?
Otherwise you would need to setup a separate management network. Use something like a Z3C. Primary WAN going to the existing firewall. Put a SIM into it for failover. Configure the switch management to use the Z3C.
Then use AutoVPN back to a central MX67 somewhere. Then you would have a separate out of band management that could handle a local Internet failure.