Regarding AnyConnect and RSA SecurID integration, yes that is possible and you can use either the SDI protocol or RADIUS between ASA & the SecurID AM.
There are implementation guides availabe from RSA (https://community.rsa.com/docs/DOC-62877 for example) and a number of posts on the Cisco community forums on the subject. This is usually pretty straightforward.
I'm not sure if you can then run Microsoft PPTP to the TMG gateway within the AnyConnect VPN connection.
However, considering additional packet overhead, complexity and I understand that the TMG is end of life, I would suggest that you would look at ways to redesign this remote-access scenario so you would not need multiple VPN solutions on top of each other.