If you only want to add local roles or application roles and assign security, the db_securityadmin role would be a better bet.
In saying that, I'm not keen on anyone outside of the dba team to change security - or anything on the production server - I prefer it all to be controlled within the team.