If you're gonna have to look at purchasing equipment anyways to get this working, I'd suggest just getting a Sonicwall TZ 100 firewall appliance. Not only is this an business grade router, but you get added benefit of firewall protection and control, plus you can set up to 4 internal zones which will each work exactly like a VLAN. We have done this at my office and a couple other places. A TZ 100 is going to be the same price or cheaper than a Layer3 switch, but you also get the added routing and firewall capabilities all in one.
With this setup, all you need to do is configure your firewall with three LAN networks, for example:
X0: Management LAN - 192.168.0.0/24 this is the interface that you can gain access to the management side of the firewall and keep it separated from the rest of the network.
X1: Default WAN - goes to your outside modem or internet connection
X2: Accounting LAN - 192.168.2.0/24 this connects to your switch with an untagged or access switchport VLAN for your Accounting network.
X3: Staff LAN - 192.168.3.0/24 this connects to your switch with an untagged or access switchport VLAN for your Staff network.