Yes, security is done by role, so you'll need to make a role and put the one user into it. It won't be a problem to do it that way--many of our own roles only have one or two people in them (one person plus a backup who is authorized to maintain an area of a site).
Jamie