Mikrotik VPN behind ISP Router

I poked around and found variants of this question…Currently we NAT a VNC port to access internal PC. Works fine but not very safe. Looking at using Mikrotik only for VPN tunnel, then use VNC or some other remote app to tunnel in from Internet and into that internal PC without changing the existing PC static LAN. At any given time I may also have multiple cell phones remoted in to observe the PC.
I know it would probably be easier to replace the ISP router with a Mikrotik and be done with it… Any thoughts on my poorly drawn diagram?
Thank you,
GB
Mikrotik-VPN.jpg