Hello !
No , there is no way because even if in space you have set that the device is the owner of the config (NSOR) the SD does not sync automatically in order to prevent a mismatch, if 2 parties are acting simultaneous on Space and on the device.
If you use SD, then you should avoid config changes of SD manged security items on the device itself.
I know thta configuring on space is not the most elegant way, Juniper has presentations about the future 15.2 SD, where policy configuration is more intuitive and with add. features like automatic policy analysis and policy placement are programmed. At least from this presentation this look promising for me.
regards
alexander