If this is an 802.1x authenticated network, you could assign the VLAN through a returned attribute and a server derived rule on the controller.
On the controller you'd configure a server derived rule on the server group and on the RADIUS server you'd configure a rule/policy to assign the Aruba-User-Vlan attribute to that particular user. The method will vary depending on the RADIUS implementation.
Sample config on the controller. This will set the VLAN value to whatever is returned in teh Aruba-User-Vlan attribute.
aaa server-group "name-of-server-group"
set vlan condition "Aruba-User-Vlan" value-of position 1
You could also assign a unique role for that user that would have a VLAN assigned to it.