The secondary AP will be plugged in by ethernet and run in router mode.. It will not extend the network.. set it up with entirely different wireless name and security.
The people on the secondary AP will be on a different IP range, the same as the situation you have with guest network. It might make the secondary AP clients have some issues.. but it will give them basic internet access.
Place the Secondary AP in the DMZ from the TC... this is done via the Network tab as a default server.

So set the dhcp reservation for the secondary AP here.
Then click the Network Options.

And use the enable default host and use whatever IP you are running for the secondary IP.
This is not as good as running proper vlan separation in the TC itself but it should stop clients on the secondary AP having access to your LAN but you perhaps should beef up security on your side of the system.. assuming you have people with high degree of IT knowledge and the desire to gain access to your system. if you do have issues I will have to get you to so some other changes.
I will need to do a test to see if it is possible to put the secondary AP into the second vlan of the TC.. that might work.