Welcome to Microsoft Q&A Platform, thanks for posting your query here.
You can use vWAN to propagate routes between AVS ExR and VPN connecting into AWS, check this document.
This way no NAT-ing and no exposure via public IP is necessary.
One suggestion is to use NSXT public IP feature.
As mentioned in my previous response, to get exact guidance on your use case open a support case with AVS team.
Hope this helps.
If you need further help on opening support case, tag me in a comment.
If the suggested response helped you resolve your issue, please 'Accept as answer', so that it can help others in the community looking for help on similar topics.