Internet --> Router (with Public IP) --> ASA (with Private IPs) --> LAN
What I'm trying to achieve is for remote workers to be able to use the Anyconnect client to connect back to the office. Can you please advice if there are any ways to achieve this ? Basically needs to change the Listening IP address / Termination IP address of SSL Anyconnect VPN.
Yes, it is possible from Internet->Router->ASA(on private)->Lan, which means all your public-address bound traffic must be translated on the router and most likely your ASA becomes an access control point.
However if you put your ASA as well on the public address, then your router becomes a transit path and you will have fully translation taking place on the ASA itself, which is preferred from firewall administrative point of view.
If you have public IP ranges, you break the public-segment to connect your router and ASA on /30 mask and rest of the public addresses will be usable for service-hostings for cloud-base applications.