You can have a SEPM in DMZ for all roaming\WAN clients.
Do you want this only to update definitions or policies and other controls as well ?
Do you want this DMZ SEPM to be standalone or a replication partner of Production SEPM.
You can Put a SEPM in DMZ as a replication partner of production SEPm you would need to open pot 8443 between these SEPM.
Then add the FQDN or Public IP of the DMZ SEPM to the Management Server List. Then clients which are out of network will automatically be re-directed to DMZ SEPM.