As mentioned obove it makes no sense to store the PW in the script.
It does make sense as long as the script is not stored with the encrypted file, but rather only with the unencrypted server (plus backed up someplace else, like on a piece of paper in a safe offsite)
But you can use asymmetric (public key) encryption if you don't want the backing-up user to be able to decrypt at all: