First, you need to get the client cert to your device. Typically, this is done via MDM solution, but you can also just email yourself a cert in pfx format and install it on the device from email, or VPN in and obtain one via browser from your certificate enrollment service.
Then, you would go to the profile definition on your EDGE client, flip Use Certificates switch to On, and select a certificate you want to use.
Then, you can go to the VPE on the APM and add On-Demand Cert Auth action before your login page.
And don't forget to add your Clieny cert's Trusted CA under client cert settings of then clientsideSSL profile that is applied to your virtual server. Should be all set.