With a single public IP, and a Layer 3 switch...and the need to do inter-vlan routing on the switch...and HA firewalls...

You kinda don't have too many choices. You can remove the FIOS router, but you'll still have "some" router that is single, and then double NAT to your HA config.
That's why I suggested a hot/cold firewall config. That gets you to a TRANSIT model, where the WAN from the ONT is terminated directly on the switch (in a VLAN, no VE), both hot/cold firewalls have their WAN interfaces connected to that VLAN, DHCP active for WAN, but only
one firewall active at a time.