The plan sounds just fine. Creating and using geli is pretty easy. You generate the key, create new partition, encrypt it, set it's mount point and that's it. Just remember to add the appropriate lines to /etc/rc.conf after you're done. And add your geli partition to /etc/fstab so it gets mounted at boot.