@arunpatidar - Thanks! It didn't exactly have the answer, but it slowed me down enough to think about the problem more! The solution may not be ideal but does seem to work for our scenarios.
Solution:
Create an editor group, give "modify" access to the desired path, then create two ACL deny rul...