If you were doing this with Linux, you should install a common linux distribution (to make sure it won't have security problems out of the box) and then go through and turn off anything that doesn't need to be on, and check it using nmap to see what ports are still open. If you want to educate yourself and go further then download metasploit and see if you can break into it.
Install vsftpd as the ftp server, and make sure it does not allow anonymous login, and make sure the passwords are long and random. If you have ssh on it, which you probably should because you should encourage your people to use scp instead of ftp (graphical tools exist for the mac), make sure you install denyhosts or something similar to keep out the brute-forcing attacks. Try not to have commonly guessable usernames, such as "tom" or "joe" and disallow root login.
But if you have a Mac, can't you install or turn on the Mac's ssh or ftp server and do the same ? That might be simpler.
You might also google for "The Perfect Ubuntu Server" -- there is a series of howto's on how to set up the "perfect" server in various linux distributions.