Is there a way to get the VLANs to show up as interface options in the Security section so I can apply different lists and application blocking based off the VLAN?
The only option that shows up for me is LAN, which then applies everything to everything associated with LAN and the VLANS.
As regards Threat shield DNS, it could be possible by creating a zone, for example VLAN1 and include the VLAN interface, see also Zones and policies — NethSecurity documentation
Then the new zone shows up in Threat shield DNS settings so it should be possible to enable threat shield DNS for example for LAN but not for VLAN.