Kentico documentation states the "DENY" permission takes priority over any other permission. What I typically do is restrict everyone, then create roles for the different sections/nodes users need to have access to. Create a role for editor and contributor, then on each of the sections, grant or deny access on the security tab of the page. Next start assigning users to the roles as needed and test it out.