Hello ,
It is tough to implement qos if the tunnels terminate on the PIX. The router can do a lot of qos mechanisms, but in this case, the IPSEC should terminate on the router in which the links terminate. once encapsulated, any intermediate device cannot do qos.
My advice will be to change the IPSEC tunnel to the router and do WFQ on the router.
you can see the following site.
http://cisco.com/en/US/netsol/ns340/ns394/ns171/ns109/networking_solutions_white_paper09186a008018913f.shtml