bbanzai
DOT or private DNS is phone wide and can't be customized the way you wish.
You could have a specific user profile which you only activate at work (kept at rest at all other times), and use a VPN on other profiles to achieve in order to achieve better privacy against eavesdropping and MITM attacks (unencrypted traffic).
The VPN connection will also protect your DNS.
P.S. Don't forget to enable the HTTPS only mode in your web browser as well!