Hello,
It can be done using a security role allowing everybody to modify membership in the group and a business rule triggering Before adding or removing a member from a group. The rule will cancel the operation if the member being added/removed is not the initiator. Finally, you should have something like the following:
Security role
Business rule