I'm in not quite the same but remotely similar kind of a situation, with a device I got second-hand that had already been flashed with LineageOS, but without root, and sooner or later I'm going to want Magisk and hide-root and Xposed to pass SafetyNet and enable Google Pay and the security token app for my employer's VPN.
From what I've read, I'd say we need forget about TWRP for the time being, though, because there's no official version yet that would handle decryption, so it's no use for backups. Also, I don't know whether someone is working on getting such a fully-functional TWRP for