Hi Dameon,
you can implement GETvpn on the CE routers, but it will not solve your problem as the encrypted multicast packets will still be multicast (i.e. GETvpn does header preservation - it does not alter the source or destination ip address of the packets).
You'll probably want to consider implementing GRE tunnels (with or without 'tunnel protection', i.e. ipsec encryption) if it's only a few sites, or DMVPN.
hth
Herbert