Another option is WASM or WASM-style sandboxes if using another process is undesirable.
But are the compiler+OS that runs the ffmpeg executable really a sandbox ?
The most secure way presently is to use qubes-os that allows to use a very hardened VM to run individual applications.