The PCS and PPS devices have the framework for Delegated admin roles (GUI > Admin Roles > Delegated Admin Roles) under which you could create an admin role that allows access only to End Point Security policies. Note that you will have to allow access to User Realms and User Roles if you want them to create End Point Security Policies and also apply to certain realms/roles. If you only need them to create the policies and not actually apply to realms/roles then it wont be needed.